The package has a long, regular release history and clear ownership, but the repository shows no commits in the last three months. Unpinned workflow actions and absent security scanning add modest maintenance risk.
68%
Total Score
75
50
94
100
The package declares 9 runtime dependencies, which increases the number of transitive components involved in adoption. This is a moderate complexity concern for a small helpers package, though not severe by itself.
There were no commits and no active maintainers in the last three months. This is a meaningful maintenance warning, although the recent release history shows that the project was active over the broader period.
Composer build tooling is present, but no security scanning tools were detected. That leaves a modest transparency and maintenance gap.
Both workflows were analyzed successfully with no reported audit findings, and no workflow has top-level write permissions or an untrusted checkout. However, both of the two action references are unpinned, which weakens build reproducibility.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
nesbot/carbon Version ^2.0 || ^3.0 | — | — |
hyperf/context Version ~3.2.0 | — | — |
hyperf/support Version ~3.2.0 | — | — |
hyperf/tappable Version ~3.2.0 | — | — |
hyperf/macroable Version ~3.2.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.