It has an MIT license, tests, a changelog, and no install-time scripts. Organization backing and dependency scanning help, but do not offset the maintenance and package-identity concerns.
38%
Total Score
50
79
75
This is the only release, published over three years ago, with no releases in the last 12 months. That provides little evidence of ongoing maintenance.
The repository recorded zero commits and zero active maintainers in the measured three-month period, while its last push was in August 2023. This strongly raises abandonment risk.
The linked repository name does not match yii-tools/template, although its README mentions the package reference recorded by the signal. The mismatch still makes package ownership and provenance less clear.
The repository has no security policy, leaving vulnerability-reporting expectations undocumented. Dependabot is enabled, which provides some compensating security maintenance.
All four analyzed workflows use unpinned actions, which weakens build reproducibility. No dangerous triggers, untrusted checkouts, script injections, or audit findings were reported, limiting this to a hygiene concern.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
foxy/foxy Version ^1.2 | — | — |
yiisoft/files Version ^2.0 | — | — |
yiisoft/assets Version ^4.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.