Package Health

yii2-starter-kit/yii2-file-kit

It has a declared BSD license, tests, a useful README, and no install-time scripts. Its modest dependency set and organization backing help, but repository security documentation is limited.

Latest 2.2.0PackagistPackagist

68%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

75

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

88

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

75

Health Score Breakdown

Release historycaution

The package has existed for nearly eight years with 30 releases, but only one release in the last 12 months indicates a slow cadence. The recent 2026 release provides some evidence of ongoing publication, so this is a caution rather than a severe abandonment signal.

Repo commit activitycaution

There were no commits and no active maintainers during the last three months. Although a recent release shows some publication activity, the current development pause raises maintenance risk.

Repo toolingcaution

The repository uses Composer for builds, but no security scanning tools are configured. This is a transparency and maintenance gap, not evidence that the package is unsafe.

Security policycaution

The repository has no security policy, leaving vulnerability reporting and response expectations undocumented.

Workflow auditcaution

The sole workflow was fully analyzed with no dangerous triggers or audit findings, but its one action reference is unpinned. The missing top-level permissions block is acceptable on its own and does not offset the pinning gap.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

Eugene Terentev
Victor Gonzalez

Direct Dependencies

DependencyLast ReleaseScore
league/flysystem
Version ^3.0
—
—
yiisoft/yii2-jui
Version ^2.0.0
—
—
rmrevin/yii2-fontawesome
Version ^3.4
—
—
npm-asset/blueimp-file-upload
Version ^9.7.0
—
—

Weekly Downloads

Info

Last Published
6 months ago
Created
12 years ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform