The package includes tests, a readable README, an MIT license, and a source repository that matches its name. It lacks security scanning and a security policy, limiting maintenance transparency.
56%
Total Score
50
80
75
This is the package's only release, published about 8 years ago, with no releases in the last 12 months. The repository was pushed more recently, but the registry artifact itself shows prolonged release inactivity.
The repository recorded 0 commits and 0 active maintainers in the last 3 months, indicating no recent development activity. This reinforces the stale release history.
Composer and Phing provide build tooling, which is positive, but no security scanning tool is configured. The missing scan reduces assurance without making the release unfit on its own.
The repository has no security policy, leaving vulnerability reporting and response expectations undocumented. This is a transparency gap for a project template handling authentication-related code.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
yiisoft/yii2 Version ~2.0.13 | — | — |
yiisoft/yii2-queue Version ~2.0.2 | — | — |
yiisoft/yii2-bootstrap Version ~2.0.7 | — | — |
yiisoft/yii2-swiftmailer Version ~2.0.7 | — | — |
yidas/yii2-composer-bower-skip Version ~2.0.13 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.