The package includes tests, a README, a small dependency set, and a matching repository backed by an organization. Confirm which license governs your use before pinning this release.
55%
Total Score
75
100
79
50
The manifest declares MIT, but the artifact license file was detected as GPL-2.0. Although a license file is present, this mismatch creates uncertainty about the terms governing use.
The package has had no release in about three years and five months, with zero releases in the last 12 months. Its short release history limits evidence of ongoing maintenance.
The repository recorded zero commits and zero active maintainers in the last three months, consistent with several years of inactivity and raising abandonment concerns.
Composer is used for builds, but no security scanning tools are configured. The missing scanning is a modest transparency and maintenance gap, not evidence of unsafe code.
The repository has no security policy, leaving no documented route for reporting vulnerabilities. This is a transparency gap for a package intended to be integrated into applications.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
yiisoft/yii2 Version * | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.