Usable with caveats: the package is licensed, clearly backed by its matching organization repository, and has a stable release history, but it has had no release or commit activity for more than two years. Workflow permission and security-tooling gaps add maintenance and supply-chain hygiene concerns.
55%
Total Score
75
81
50
One of two workflows uses pull_request_target, which can increase CI supply-chain exposure when handling untrusted pull requests. No untrusted checkout or script-injection patterns were detected, limiting the concern.
A consumer-facing README is present and the release has a GitHub release marker. Missing tests and changelog files in the published artifact are normal packaging practice, while the repository's lack of tests and changelog is a modest project-hygiene gap.
The package has 34 releases since October 2022, but its latest release was in December 2023 and there have been no releases in the last 12 months. This indicates a materially stale release cadence despite earlier activity.
The repository recorded zero commits and zero active maintainers in the last three months, consistent with the long gap since the latest release. The non-archived status provides some reassurance but does not offset the current inactivity.
Composer build tooling is present, but no security scanning tools were detected. This is a transparency and maintenance gap, though it is not by itself evidence that the package is unsafe.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
hyperf/di Version ~3.1.0 | — | — |
hyperf/event Version ~3.1.0 | — | — |
hyperf/logger Version ~3.1.0 | — | — |
hyperf/context Version ~3.1.0 | — | — |
hyperf/support Version ~3.1.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.