The package includes tests, a substantial README, and a license file, while its organization-backed repository remains active with two recent contributors. Its broad runtime dependency set, absent security policy, and install-time scripts warrant routine review.
78%
Total Score
100
50
89
67
Twenty-five runtime dependencies create a broad integration and update surface for a package that depends on a large Hyperf ecosystem, though the profile is coherent with its described service-module role.
The package runs post-autoload-dump and post-root-package-install scripts, which add install-time behavior and deserve review, but this is not severe on its own.
Composer build tooling is present, but no security-scanning tooling was detected, leaving a modest transparency and maintenance-process gap.
The repository has no security policy, which weakens the documented process for reporting and handling vulnerabilities, but it is not a severe dependency-health risk by itself.
The assessed version is not a stable major release, but it is not marked prerelease and recent prerelease share is zero, reducing the practical concern.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
hyperf/amqp Version ^3.1 | — | — |
hyperf/phar Version ~3.1.0 | — | — |
hyperf/cache Version ^3.1 | — | — |
hyperf/redis Version ~3.1.0 | — | — |
symfony/yaml Version ^6.4 || ^7.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.