Healthy and reasonable to depend on, with some maintenance and workflow caveats. It has regular releases, a matching organization-backed repository, clear licensing, and release notes, but recent repository activity is limited to one contributor and its GitHub workflows lack explicit token permissions.
78%
Total Score
63
100
89
80
One of two workflows uses pull_request_target, which can be risky when handling untrusted pull requests, although no untrusted checkout or script-injection pattern was detected.
All recent repository commits came from one contributor. Organization backing provides some handoff capacity, but the observed short-term activity still has a concentrated maintainer base.
Only one commit was made in the last three months by one active maintainer, which is thin recent development activity despite the regular registry release history.
There are no open issues or pull requests, but there was also no issue or pull-request activity in the last month, providing little evidence of an active user or maintainer feedback loop.
The repository has only 2 stars and no forks, so there is little external adoption evidence; popularity is supporting evidence rather than a decisive health measure.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
hyperf/support Version ~3.2.0 | — | — |
hyperf/database Version ~3.2.3 | — | — |
hyperf/tappable Version ~3.2.0 | — | — |
hyperf/stringable Version ~3.2.0 | — | — |
symfony/polyfill-php85 Version ^1.33 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.