A single maintainer, no recent issue or pull-request activity, and no security policy reduce confidence in ongoing support. The MIT license, tests, readable documentation, and non-archived matching repository provide useful adoption safeguards.
45%
Total Score
33
50
78
75
The package has had no releases in the last 12 months, and its latest release was published nearly five years ago. Its 41-release history shows prior activity but does not offset the current maintenance gap.
There were no commits and no active maintainers in the last three months. Combined with the old last push, this is strong evidence that active maintenance has stopped.
The package declares 15 runtime dependencies, including several UI and asset packages, creating a relatively broad dependency surface for a Yii2 module. No provided signal shows that these dependencies are unsafe or unmaintained, so this is a moderate transparency concern rather than a severe risk.
The registry namespace and repository owner match, but the owner is an individual account rather than an organization. This provides consistent ownership evidence without demonstrating broader project backing.
There were no new or closed issues and no new or merged pull requests in the last month. The absence of recent contribution activity supports the maintenance concern, although the open-issue count is unknown.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
yiisoft/yii2 Version ^2.0.20 | — | — |
bower-asset/swiper Version ^6.3.5 | — | — |
npm-asset/highlight.js Version ^9.18.1 | — | — |
arogachev/yii2-sortable Version ^0.1.6 | — | — |
yiisoft/yii2-bootstrap4 Version ^2.0.4 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.