The package is clearly identified and licensed, with a README and a GitHub release. Its single-user backing and minimal repository provide little evidence of ongoing maintenance, while the broad runtime dependency set adds upkeep risk.
35%
Total Score
33
50
64
88
This package has only one release, published in August 2019, with no releases in the following seven years. That strongly indicates abandonment risk for a dependency.
The repository recorded zero commits and zero active maintainers in the last three months, consistent with the long release gap and offering no evidence of current maintenance.
The package declares nine runtime dependencies, including several Yii extensions, despite being a development-time generator. This increases compatibility and maintenance exposure for a package with no recent releases.
The package has one registry maintainer and is backed by a personal repository. A single maintainer is not inherently unhealthy, but it leaves limited visible maintenance capacity for a dormant project.
The registry namespace and repository owner match, but both identify a personal account rather than an organization. This supports package identity while leaving limited visible project backing.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
yiisoft/yii2 Version * | — | — |
kartik-v/yii2-grid Version * | — | — |
kartik-v/yii2-builder Version * | — | — |
kartik-v/yii2-helpers Version * | — | — |
kartik-v/yii2-widgets Version * | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.