Usable with caveats: it has a long release history and recent registry releases, but repository development has been inactive for about six months and the project has little external adoption or security documentation.
58%
Total Score
67
100
83
83
A README is present, but it is only 342 characters and provides minimal usage guidance. The absent tests and changelog are not concerns for the published artifact because those normally belong in the source repository.
The registry namespace and repository owner match, and the owner is an individual account rather than an organization. This is consistent ownership, but it indicates a relatively narrow project backing.
The repository recorded 0 commits and 0 active maintainers during the last 3 months, despite the package's active release history. This gap between publishing and source development raises a meaningful maintenance risk.
The repository has only 4 stars, 0 forks, and 1 watcher, indicating limited external adoption. Popularity is supporting evidence rather than decisive on its own, but it provides little additional confidence here.
Composer is used as a build tool, providing basic project build structure, but no security scanning tooling is configured. The missing scanning is a transparency gap for a package with many application-facing components.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
yiisoft/yii2 Version ~2.0.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.