Clear documentation, a matching repository, and a steady release history improve confidence. Pin the two workflow actions before relying on the project's automation.
72%
Total Score
75
100
88
100
The repository recorded no commits and no active maintainers in the last three months, which is a meaningful maintenance concern despite the recent release history.
The repository has 1 star, 0 forks, and 1 watcher, indicating a very small public user base; this is supporting caution rather than evidence of abandonment by itself.
Composer build tooling is present, but no security scanning tools are configured, leaving a modest transparency and maintenance gap.
Both workflows were analyzed with no audit findings or untrusted checkouts, and the pull_request_target trigger has no detected sink. However, both action references are unpinned, creating a workflow supply-chain hygiene gap.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
hyperf/di Version ~3.2.0 | — | — |
hyperf/codec Version ~3.2.0 | — | — |
hyperf/event Version ~3.2.0 | — | — |
hyperf/command Version ~3.2.0 | — | — |
hyperf/support Version ~3.2.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.