The package is well documented, regularly released, and clearly connected to its source project. Organization ownership and a security policy provide useful continuity, though the project has limited recent activity.
70%
Total Score
67
94
83
All recent commits came from one contributor, so maintenance could be disrupted if that person becomes unavailable; organization backing provides only partial compensation because no second recent contributor is shown.
Only 2 commits were recorded in the last 3 months, indicating limited recent source activity despite the stronger registry release cadence.
Composer build tooling is present, but no repository security-scanning tool was detected. The separate security policy helps transparency but does not replace automated scanning.
The audit completed cleanly with no detected injection or high-severity findings, but both analyzed action references are unpinned, leaving workflow dependencies exposed to changing upstream code.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
hyperf/di Version ~3.2.0 | — | — |
hyperf/support Version ~3.2.0 | — | — |
symfony/mailer Version ^6.4 || ^7.0 | — | — |
hyperf/contract Version ~3.2.0 | — | — |
hyperf/macroable Version ~3.2.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.