The MIT license, source tests, and stable release provide a sound baseline. Workflow pinning, absent security tooling, and a relatively large runtime dependency set add smaller maintenance concerns.
52%
Total Score
0
50
79
50
The latest release was about 2 years and 4 months ago, with no releases in the last 12 months; the ten-release history shows an initially active project that has since stopped publishing.
There were zero commits and zero active maintainers in the last 3 months, consistent with the release pause and indicating current maintenance capacity is weak.
Nineteen runtime dependencies, including several Hyperf components and Redis, create a broad compatibility surface and increase maintenance burden, though the dependency set is coherent with the package's metrics role.
Composer build tooling is present, but no security scanning tools were detected, leaving a modest transparency and maintenance gap.
The repository has no security policy, which makes vulnerability reporting and response expectations unclear for a package with many runtime dependencies.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
hyperf/pool Version ^3.1 | — | — |
hyperf/codec Version ~3.1.0 | — | — |
hyperf/event Version ^3.1 | — | — |
hyperf/utils Version ~3.1.0 | — | — |
hyperf/engine Version ^2.3 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.