The single-maintainer project has no declared or detected license, and its workflow uses three unpinned actions. A README and Composer build setup help, but the small project offers limited security and maintenance transparency.
56%
Total Score
50
50
50
Neither the package metadata nor the linked repository contains a declared or detected license file. That creates a material legal and transparency gap for a dependency.
Only one registry publishing maintainer is listed, and the project backing is an individual account rather than an organization. This leaves a thin apparent maintainer base if that person becomes unavailable.
The latest release was published in April 2024, with no releases in the following roughly two years and five months. Its 27-release history shows prior activity, but the current pause lowers confidence in ongoing maintenance.
The repository recorded no commits and no active maintainers in the last three months, consistent with the extended release gap. This indicates little recent maintenance capacity.
Composer is used for builds, which is appropriate for this PHP package, but no security scanning tooling is present. The missing scanning is a modest transparency gap rather than evidence of a defect.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
yiisoft/yii2 Version ^2.0.5 | — | — |
kartik-v/yii2-password Version ^1.5.3 | — | — |
kartik-v/yii2-widget-select2 Version ^2.1.0 | — | — |
kartik-v/yii2-widget-datepicker Version ^1.4.0 | — | — |
kartik-v/yii2-widget-datetimepicker Version ^1.4.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.