The 25-release history, stable 2.2.7 line, and clear documentation support dependable adoption. Licensing, repository tests, security policy, and read-only workflows are all in place; the slower registry cadence is the main limitation.
86%
Total Score
100
100
94
100
The package is mature, with 25 releases since 2013, but it has had no registry release in the last 12 months. Recent repository activity partly offsets the slower release cadence.
| Title | Versions | Severity |
|---|---|---|
CVE-2020-36655 yiisoft/yii2-gii is vulnerable to Improper Control of Generation of Code ('Code Injection') in versions 0.0.0 - 2.2.2. | 0.0.0 - 2.2.2 | High |
CVE-2022-34297 yiisoft/yii2-gii is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in versions 0.0.0 - 2.2.4. | 0.0.0 - 2.2.4 | Medium |
| Dependency | Last Release | Score |
|---|---|---|
yiisoft/yii2 Version ~2.0.46 | — | — |
phpspec/php-diff Version ^1.1.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.