Security coverage is absent, and the small repository footprint offers little operational reassurance. Its documentation and licensing are clear, but that does not make long-term support dependable.
12%
Total Score
0
50
75
Packagist marks the entire package as abandoned, with no replacement package provided. Package-level abandonment is a severe warning for a new dependency.
The latest release was published on January 11, 2016, and there have been no releases in more than 10 years. The historical release cadence does not compensate for the prolonged release gap.
The repository recorded zero commits and zero active maintainers in the last three months, consistent with its archived state. This provides no evidence of ongoing maintenance capacity.
The linked repository is archived, and it was last pushed on January 11, 2016. An archived source repository indicates the project is no longer maintained.
Composer build tooling is present, but no security-scanning tools were detected. The build setup is useful, yet it offers limited assurance for an unmaintained package.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
yiisoft/yii2 Version * | — | — |
yiisoft/yii2-jui Version * | — | — |
yiisoft/yii2-bootstrap Version * | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.