Usable with caveats: the release is licensed, clearly backed by its matching repository, and includes tests and a substantial README. However, it has had only two releases and no commits or active maintainers in the last three months, with no security scanning or policy.
58%
Total Score
67
100
83
70
The repository recorded zero commits and zero active maintainers in the last three months, a meaningful warning that maintenance may have stalled.
The package runs four Composer lifecycle scripts, including pre-install and pre-update commands, increasing installation complexity and requiring review before use, although this can be normal for an application skeleton.
There are only two releases, both within a four-day period, and no newer release is shown after the latest release on January 27, 2026; this is limited evidence of sustained maintenance.
The repository has only 5 stars and no forks or watchers, indicating limited external adoption; popularity is supporting evidence rather than a decisive defect for a small skeleton project.
Composer build tooling is present, but no security scanning tools are configured, leaving a transparency and maintenance-control gap.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
hyperf/cache Version ~3.1.0 | — | — |
hyperf/config Version ~3.1.0 | — | — |
hyperf/engine Version ^2.10 | — | — |
hyperf/guzzle Version ~3.1.0 | — | — |
hyperf/logger Version ~3.1.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.