This release appears usable and reasonably well-backed, with a valid BSD-3-Clause license, stable non-prerelease versioning, an active non-archived repository, repository tests and changelog coverage, security scanning, and no install-time lifecycle scripts. The main concerns are that the package is only 13 days old, all nine recent commits come from one contributor, the repository has no observed adoption activity, and both GitHub Actions workflows omit top-level token permissions. The YiiRocks organization provides some backing for the concentrated maintainer base, but the package remains young and should be adopted with normal review and upgrade monitoring.
72%
Total Score
90
100
89
90
The package is only 13 days old with four releases and a median interval of about 3 days, showing active initial development but providing little evidence of long-term maintenance.
One contributor made all nine commits in the last three months, creating a genuine bus-factor concern; organization ownership provides some potential handoff capacity but does not remove the observed concentration.
The repository has zero stars and forks and one watcher, providing no meaningful external adoption signal; this is a supporting caution rather than a standalone health verdict for a new package.
Both workflows omit top-level token permissions, leaving workflow token scope less explicit than recommended even though no workflow declares top-level write access.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
yiirocks/voyti-2fa Version ^1.0 | — | — |
report-uri/passkeys-php Version ^2.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.