Clear licensing, repository tests, and a security policy support dependable project practices. Organization backing and three active contributors reduce single-maintainer risk.
86%
Total Score
100
100
94
100
This is a mature package with 36 releases over more than 12 years, but it has had no registry release in the last 12 months. Recent repository activity partly offsets the slower registry cadence.
All five workflows were analyzed successfully, use read-only permissions, and had no audit findings or untrusted checkouts. Four of five action references are unpinned, a modest reproducibility and supply-chain hygiene gap.
| Title | Versions | Severity |
|---|---|---|
CVE-2023-50714 yiisoft/yii2-authclient is vulnerable to Improper Authentication in versions 0.0.0 - 2.2.15. | 0.0.0 - 2.2.15 | Medium |
CVE-2023-50708 yiisoft/yii2-authclient is vulnerable to Observable Discrepancy in versions 0.0.0 - 2.2.14. | 0.0.0 - 2.2.14 | Low |
| Dependency | Last Release | Score |
|---|---|---|
yiisoft/yii2 Version ~2.0.13 | — | — |
paragonie/random_compat Version >=1 | — | — |
yiisoft/yii2-httpclient Version ~2.0.5 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.