The small community and missing security policy reduce confidence in long-term support. Clear licensing, documentation, a matching organization repository, and no install scripts keep the release from being a poor dependency choice.
58%
Total Score
75
100
86
75
The package has 18 releases and a five-day median interval, but it has had no release in more than three years. That long gap materially raises abandonment risk despite its earlier activity.
The repository recorded zero commits and zero active maintainers in the last three months, consistent with the extended release pause and weakening confidence in ongoing maintenance.
Four stars and two forks indicate a very small user and contributor base, so there is limited visible community support if maintenance issues arise.
The repository has no security policy, leaving no documented process for reporting or handling security issues. This is a transparency and maintenance gap, though not evidence of a security incident.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
yiisoft/yii2 Version ^2.0.40 | — | — |
wdmg/yii2-base Version ^1.3.0 | — | — |
wdmg/yii2-helpers Version ^1.4.2 | — | — |
wdmg/yii2-selectinput Version ^1.0.9 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.