The BSD-3-Clause license, complete template documentation, tests, and modest dependency set support adoption. Composer install scripts and no repository security policy add smaller maintenance concerns.
40%
Total Score
0
100
79
67
The latest release was published on November 27, 2017, with no releases in the last 12 months despite the package being over 10 years old. This is strong evidence of abandonment risk.
The repository recorded zero commits and zero active maintainers in the last 3 months, matching the long release gap rather than showing ongoing maintenance.
The package runs post-create-project-cmd and post-install-cmd Composer scripts. Install-time automation deserves review because it executes during setup, although the signal does not show malicious behavior by itself.
The repository uses Composer, but no security scanning tools are configured. This is a maintenance and transparency gap, though it is secondary to the stale activity.
No security policy is present in the repository, leaving vulnerability reporting expectations undocumented. The package's tests and license provide some transparency but do not replace this process.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
yiisoft/yii2 Version ~2.0.5 | — | — |
yiisoft/yii2-bootstrap Version ~2.0.0 | — | — |
yiisoft/yii2-swiftmailer Version ~2.0.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.