The package is small and easy to inspect, but it offers little testing or security-process evidence. Pin v3.0.3 and validate it against your Yii2 version before adoption.
36%
Total Score
71
75
The latest release was in March 2016, with no releases in the last 12 months despite a stable version. This is strong evidence of abandonment risk for a dependency.
The repository name does not match the package name and its README does not mention the package, so the source-package relationship is not clearly established.
The repository is not archived, which avoids an explicit abandonment marker, but its last push was in March 2017 and does not offset the long release gap.
The repository has no security policy. For an old web extension this reduces transparency and leaves no documented channel or process for handling security reports.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
yiisoft/yii2 Version ^2.0 | — | — |
voskobovich/yii2-alert Version ^1.0 | — | — |
vova07/yii2-imperavi-widget Version ^1.0 | — | — |
voskobovich/yii2-base-toolkit Version ^2.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.