Its dependency list is small and the repository still matches the package. Consumer documentation and project safeguards are sparse, with no README, tests, changelog, or security policy; the long period without activity makes future fixes unlikely.
38%
Total Score
0
100
67
83
The latest release was in April 2016, with no releases in the last 12 months despite the package being over 10 years old. This is strong evidence of abandonment risk.
The repository recorded zero commits and zero active maintainers in the last 3 months, consistent with the release history and indicating no current maintenance.
The artifact has no README, while missing tests and a changelog are normal packaging practice; the exact version does have a GitHub release. The missing consumer documentation is still a transparency gap for a Yii2 module.
The linked repository is not archived, but its last push was in April 2016. The unarchived status is mildly reassuring, while the old activity date leaves the maintenance concern intact.
The linked repository has no security policy, leaving no documented route for reporting vulnerabilities. This adds a modest transparency concern but does not by itself show the package is unsafe.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
yiisoft/yii2 Version * | — | — |
worstinme/yii2-uikit Version * | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.