Usable with caveats: it has a long release history, recent versioned releases, organizational backing, and a matching source repository. No commits were recorded in the last three months, and the repository’s workflows have avoidable permission and pull-request risks.
74%
Total Score
83
100
94
75
One of two analyzed workflows uses pull_request_target, which can increase exposure to untrusted pull-request content even though no untrusted checkout or script injection was detected.
No commits and no active maintainers were recorded during the last three months. This is a meaningful maintenance concern, although the recent release history provides some compensating evidence.
Composer build tooling is present, but no security scanning tools were detected. For a small package this is a hygiene gap rather than evidence of abandonment.
Both workflows omit top-level token permissions, making least-privilege behavior less explicit. No workflow declares top-level write access, which limits the severity of this gap.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
hyperf/di Version ~3.2.0 | — | — |
hyperf/database Version ~3.2.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.