Its small codebase is tested and clearly licensed, which limits transparency concerns. One registry maintainer and no security scanning leave little visible support for future fixes.
35%
Total Score
25
79
The package has had no releases in more than four years, despite eight releases overall, indicating prolonged abandonment rather than an actively maintained release line.
The repository recorded zero commits and zero active maintainers in the last three months, with its last push in February 2022; this strongly supports the abandonment concern.
Only one registry account has publishing access. Because this is a user-owned project rather than organization-backed infrastructure, the narrow publishing base provides little redundancy if that maintainer stops responding.
Composer build tooling is present, but no security scanning tools were detected, leaving a maintenance and transparency gap alongside the stale project activity.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
psr/log Version ^1.0 | — | — |
hyperf/rpc Version 2.2.* | — | — |
hyperf/utils Version 2.2.* | — | — |
psr/container Version ^1.0 | — | — |
google/protobuf Version ^3.16 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.