Usable with caveats: the package is actively released, clearly licensed, and backed by an organization, but the repository shows no commits or active maintainers in the last three months. A pull-request workflow and missing explicit workflow token permissions add maintenance and automation concerns.
68%
Total Score
75
100
89
75
One of two analyzed workflows uses pull_request_target, which can expose elevated automation context when handling pull requests; no untrusted checkout or script injection was detected to offset the risk.
The repository recorded 0 commits and 0 active maintainers in the last 3 months. The recent release history partly offsets this, but the lack of current source activity is a real maintenance concern.
There are no open issues or pull requests and no issue or pull-request activity in the last month, leaving little evidence of an active contributor or support community.
The repository has only 1 star and 1 fork, providing little independent adoption evidence; this is supporting evidence rather than a standalone health failure.
Composer build tooling is present and a security policy exists, but no security scanning tools were detected, leaving a modest transparency and maintenance gap.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
hyperf/support Version ~3.2.0 | — | — |
composer/composer Version ^1.0 || ^2.0 | — | — |
hyperf/collection Version ~3.2.0 | — | — |
hyperf/filesystem Version ~3.2.0 | — | — |
hyperf/stringable Version ~3.2.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.