The repository has no security policy or security scanning, leaving limited formal support for handling future issues. A clear README, exact-version release notes, matching repository, and MIT declaration improve transparency.
62%
Total Score
50
83
50
This is the package's first release, published 0 days ago, so there is no release track record yet; the lack of history limits confidence rather than proving abandonment.
The repository has 0 commits and 0 active maintainers in the last 3 months, matching its same-day launch. This provides no demonstrated ongoing maintenance capacity yet.
Composer is used for the build, which is appropriate, but no security-scanning tools are configured. The missing scanning weakens supply-chain maintenance practices.
The repository has no security policy, reducing transparency about vulnerability reporting and response. This is a hygiene and support gap, not evidence that the package is unsafe.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
hyperf/di Version ^2.2 || ~3.1.0 | — | — |
hyperf/config Version ^2.2 || ~3.1.0 | — | — |
psr/container Version ^1.1 || ^2.0 | — | — |
psr/http-message Version ^1.0 || ^2.0 | — | — |
psr/http-server-handler Version ^1.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.