Its small footprint and absent security policy add little confidence. The MIT license and matching source repository improve transparency, but the project offers limited evidence of ongoing support.
38%
Total Score
50
50
78
75
The package has had only two releases, both in October 2019, with no releases in roughly six years. That is strong evidence of stalled maintenance for a runtime framework.
There were no commits and no active maintainers in the last three months, consistent with the repository having been inactive since 2019. This materially raises abandonment risk.
Four runtime requirements, including Swoole and mbstring extensions, form a meaningful but not unusually broad dependency surface. No development dependencies are declared, so build coverage is limited but not decisive.
Five stars, no forks, and one watcher indicate a very small user and contributor footprint. Popularity is only supporting evidence, but this provides little maintenance buffer.
Composer is used for builds, but no security scanning tools are present. The missing scanning is a hygiene gap rather than proof of unsafe code.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
cockroach/cockroach Version ~1.0.1 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.