The package has an MIT license, a README, and release notes for this version. Its unpinned workflow references and lack of security scanning add maintenance overhead.
12%
Total Score
50
56
75
Packagist marks the entire package as abandoned, with no replacement provided. This is a severe adoption risk because future maintenance and support are formally withdrawn.
The repository recorded zero commits and zero active maintainers in the last three months, consistent with the archived state and indicating no current development capacity.
The linked repository is archived, despite a last push in November 2025. An archived source project is not an active maintenance base for a dependency.
The package has 50 releases since July 2022 but none in the last 12 months; its latest release was in February 2025. Earlier regular releases do not compensate for the current halt.
Composer is used as the build tool, but no security scanning tools were detected. This is a secondary hygiene gap rather than the primary adoption blocker.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
hyperf/config Version ~3.2.0 | — | — |
hyperf/logger Version ~3.2.0 | — | — |
nesbot/carbon Version ^2.0 || ^3.0 | — | — |
hyperf/support Version ~3.2.0 | — | — |
hyperf/coroutine Version ~3.2.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.