The package has a clear README, matching repository, declared GPL-3.0+ license, and no install-time scripts. Its broad dependency set and lack of security scanning make future upkeep harder to verify.
43%
Total Score
0
50
75
83
Only two releases were published, both in July 2023, with no release in the following three years. This is strong evidence of abandonment risk for a package intended as an application dependency.
The repository recorded no commits and no active maintainers in the last three months. Combined with the long release gap, this suggests maintenance has effectively stalled.
The package declares 12 runtime dependencies, including several application-specific extensions and UI components. This creates a relatively broad compatibility and maintenance surface for a small package.
Composer is used as the build tool, which is appropriate for this PHP package, but no security scanning tools are present. That leaves dependency and repository hygiene less independently checked.
The linked repository has no security policy. This is a transparency gap for a package containing controllers, uploads, migrations, and administrative functionality.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
yiisoft/yii2 Version ~2.0.5 | — | — |
select2/select2 Version >=4.0 | — | — |
thefx/yii2-user Version dev-master | — | — |
yiisoft/yii2-jui Version ~2.0.0 | — | — |
intervention/image Version ^2.5 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.