The substantial README, tests, release notes, and matching repository support practical adoption. The MIT declaration conflicts with the detected BSD-3-Clause license, while all two workflow actions are unpinned and no security policy is provided.
59%
Total Score
50
80
50
The artifact declares MIT and includes a license file, but the detected license text is BSD-3-Clause. The repository also has a license file, so this is a license-consistency concern rather than an absence of licensing.
The package has nine releases over about three years, but none in the last 12 months; the latest release was published about 16 months ago. This weakens confidence that the template is actively maintained.
The repository recorded zero commits and zero active maintainers in the last three months. Although it was pushed more recently than the assessed release, the current lack of development activity raises abandonment risk.
The repository has no security policy. This is a transparency and reporting gap, though it is not evidence that the package is unsafe by itself.
The single workflow was fully analyzed, uses read-only permissions, and has no dangerous audit findings. However, both of its two action references are unpinned, leaving the workflow exposed to upstream action changes.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
yiisoft/yii2 Version ~2.0.49 | — | — |
ustadev/telegram Version dev-main | — | — |
vlucas/phpdotenv Version ^5.6 | — | — |
alexantr/yii2-tinymce Version ^1.0 | — | — |
alexantr/yii2-elfinder Version ^1.8 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.