The MIT license and readable documentation make adoption easier, while the small repository footprint limits confidence in long-term support. No security policy is provided, adding a transparency gap for a package that handles authorization.
38%
Total Score
50
100
75
75
The latest release was published in December 2017, and there were no releases in the last 12 months. The package has therefore had no demonstrated release maintenance for more than eight years.
There were no new or closed issues or pull requests in the last month. With the repository already inactive for years, this is consistent with limited ongoing maintenance rather than active support.
The repository has only 1 star, 1 fork, and 1 watcher. Popularity is supporting evidence rather than a verdict, but these counts provide little evidence of a broad active user or contributor base.
The repository is not archived, which avoids an explicit abandonment marker, but its last push was in December 2017 and does not offset the long release gap.
The linked repository has no security policy. That is a transparency gap for an authorization-management library, although it does not by itself show that the release is unsafe.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
yiisoft/yii2 Version * | — | — |
yiisoft/yii2-jui Version ~2.0.0 | — | — |
yiisoft/yii2-bootstrap Version * | — | — |
yongtiger/yii2-application Version * | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.