The four-file artifact includes a README and license, but no tests or security policy. The GPL-2.0 license and matching repository make its contents identifiable; maintenance evidence is not sufficient for a new dependency.
12%
Total Score
0
50
50
Packagist marks the entire package as abandoned, with no replacement named. This is a direct warning that new projects should not depend on it.
The package has had 4 releases since April 2015, with no releases in the last 12 months and the latest release about 11 years ago. This strongly indicates it is no longer maintained.
The repository recorded 0 commits and 0 active maintainers in the last 3 months, consistent with the archived state and lack of ongoing maintenance.
The linked repository is archived, and its last push was about 7 years ago. Archived source is a severe abandonment risk for a dependency.
The repository has no security policy, leaving no documented process for reporting or handling security issues. This adds a transparency concern, especially for an unmaintained dependency.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
yiisoft/yii2 Version * | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.