The project is young and all recent commits come from one contributor, which limits evidence of long-term resilience. Licensing, documentation, tests in the repository, release notes, security reporting, and active tooling provide useful support.
70%
Total Score
83
93
100
The package is only 40 days old with two releases, so its maintenance history and long-term stability are not yet well established.
One contributor made all 21 commits in the last three months, leaving the project dependent on a single active developer and creating a meaningful continuity risk.
Both workflows were analyzed with no reported audit findings and no untrusted trigger sinks; however, both action references are unpinned, which weakens build reproducibility and supply-chain hygiene.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
yiisoft/html Version ^3.9 || ^4.0 | — | — |
yiisoft/view Version ^12.0 | — | — |
psr/container Version ^1.0 || ^2.0 | — | — |
yiisoft/session Version ^3.0 | — | — |
yiisoft/yii-view-renderer Version ^7.3 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.