The repository had no commits in the last three months and has only one star, limiting evidence of broader support; both workflow references are also unpinned. MIT licensing, a focused dependency set, and a documented security policy provide useful safeguards.
76%
Total Score
75
100
89
75
The repository recorded zero commits and zero active maintainers in the last three months. This weakens evidence of ongoing maintenance even though the registry release history remains active.
The repository has one star, no forks, and one watcher, indicating very limited visible adoption and a small external support signal. Low popularity alone does not outweigh the regular release cadence.
Composer build tooling is present, but no security scanning tools were detected. The repository's separate security policy partly offsets this hygiene gap.
Both workflows were analyzed successfully and no audit findings or dangerous untrusted sinks were reported. However, both of the two action references are unpinned, leaving their exact revisions mutable.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
hyperf/engine Version ^2.0 | — | — |
hyperf/context Version ~3.2.0 | — | — |
hyperf/support Version ~3.2.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.