Usable with caveats: the package is clearly licensed, documented, small in scope, and backed by a matching repository with tests. However, its last release and repository update were in November 2018, with no recent commits, so maintenance risk is significant.
58%
Total Score
0
100
71
75
The package has seven releases since May 2017, but none in the last 12 months and the latest release was published in November 2018. This long period without releases materially increases abandonment and compatibility risk.
The repository had zero commits and zero active maintainers in the last three months. For a small, mature extension this may reflect stability, but the gap is long enough to raise abandonment risk.
Composer is used as the build tool, which is appropriate for this PHP package. No security scanning tools are present, a modest transparency and maintenance gap for a dependency published for long-term use.
The linked repository is not archived, but it was last pushed in November 2018. The unarchived status is positive, while the old update date reinforces the maintenance concern shown by release history.
The repository has no security policy. This is not evidence of unsafe behavior, but it leaves vulnerability-reporting and maintenance expectations undocumented.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
yiisoft/yii2 Version ~2.0.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.