The project has had no commits or releases for more than three years, and its single-maintainer structure offers limited visible maintenance capacity. A substantial README, declared Apache-2.0 license, stable version, and no install scripts provide useful safeguards, but the lack of tests and security tooling leaves weaker ongoing assurance.
58%
Total Score
25
50
81
75
There were zero commits and zero active maintainers in the last three months, indicating no observed current development activity.
Six runtime requirements, including Workerman, MySQL support, and a routing library, create a moderate dependency surface for a service package. The profile is understandable but increases the number of components that must remain compatible.
The package and repository are owned by the same individual account, providing clear ownership but no organization backing or broader institutional maintenance capacity.
The package has only three releases, with the latest published more than three years ago and no releases in the last 12 months. This is meaningful evidence of limited ongoing maintenance for a service library.
Composer is used for builds, providing basic project tooling, but no security scanning tools are configured. That is a modest transparency and assurance gap rather than a severe risk by itself.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
workerman/mysql Version ^1.0 | — | — |
nikic/fast-route Version ^1.3 | — | — |
workerman/crontab Version ^1.0 | — | — |
workerman/workerman Version ^4.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.