The project has a clear README, repository tests, an MIT license, and ten releases in the last year. Maintenance is concentrated in one contributor, with only two commits in three months, while the workflow uses two unpinned actions and one archived action.
68%
Total Score
50
100
50
One contributor made all recent commits, so maintenance depends entirely on a single individual.
Only two commits were made in the last three months, which is limited activity for a package with ongoing releases.
The repository has no security policy, leaving vulnerability reporting and handling less transparent.
The sole workflow was fully analyzed and has no untrusted checkout or script-injection path, but both actions are unpinned and one uses an archived action, creating reproducibility and maintenance concerns.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
hyperf/pool Version ^3.1 | — | — |
hyperf/process Version ^3.1 | — | — |
spiral/goridge Version ^2.4 | — | — |
symfony/event-dispatcher Version ^7.0.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.