Package Health

yiisoft/yii

The package includes tests, a changelog, and a clear BSD-3-Clause license. Its organization-backed repository has security reporting and read-only workflow permissions, though releases are infrequent.

Latest 1.1.32PackagistPackagist

84%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

100

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

94

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

100

Are you affected? Scan for Free

Health Score Breakdown

Release historycaution

The package has been maintained since 2013 and released as recently as December 2025, but only one release arrived in the last 12 months with a median interval of about 259 days.

Vulnerabilities

TitleVersionsSeverity
CVE-2025-32027
yiisoft/yii is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in versions 0.0.0 - 1.1.31.
0.0.0 - 1.1.31
Medium
AIKIDO-2024-10400
yiisoft/yii is vulnerable to Prototype Pollution in versions 1.1.0 - 1.1.29.
1.1.0 - 1.1.29
Medium
CVE-2023-47130
yiisoft/yii is vulnerable to Deserialization of Untrusted Data in versions 0.0.0 - 1.1.29.
0.0.0 - 1.1.29
High
CVE-2022-41922
yiisoft/yii is vulnerable to Deserialization of Untrusted Data in versions 0.0.0 - 1.1.27.
0.0.0 - 1.1.27
High
CVE-2014-4672
yiisoft/yii is vulnerable to Improper Control of Generation of Code ('Code Injection') in versions 1.1.14 - 1.1.15.
1.1.14 - 1.1.15
High

Package versions

Maintainers

Qiang Xue
Alexander Makarov
Maurizio Domba
Carsten Brandt
Timur Ruziev
Paul Klimov
Wei Zhuo
Sebastián Thierer
Jeffrey Winesett

Direct Dependencies

No direct dependencies.

Weekly Downloads

Info

Last Published
9 months ago
Created
13 years ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform