The MIT license, included README, and clean install behavior make adoption straightforward. Its nine runtime dependencies and absent security policy add maintenance overhead.
38%
Total Score
25
50
86
67
Only two releases were published, both in March 2023, with no release in more than three years. That strongly raises abandonment risk for a package intended as an application dependency.
The repository recorded zero commits and zero active maintainers in the last three months, consistent with the unchanged release history and indicating no current maintenance activity.
Nine runtime dependencies, including framework, extension, encryption, cache, and validation components, increase compatibility and maintenance exposure compared with a small standalone package.
The registry lists one maintainer, and the project is backed by an individual repository owner rather than an organization. This creates a thin maintenance base, especially alongside the lack of recent activity.
The linked repository has no security policy, leaving vulnerability-reporting and response expectations undocumented. This is a transparency gap for a package handling CAPTCHA validation and encryption-related configuration.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
hyperf/di Version 3.0.* | — | — |
hyperf/cache Version 3.0.* | — | — |
hyperf/framework Version 3.0.* | — | — |
enoliu/encryption Version 3.0.* | — | — |
hyperf/validation Version 3.0.* | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.