The package has a clear MIT license, usable documentation, and an organization-backed repository with a security policy. Its small project footprint and unpinned workflow actions leave maintenance and build-integrity concerns.
70%
Total Score
75
100
89
88
The repository recorded zero commits and zero active maintainers in the last three months. This conflicts with the recent release cadence and warrants caution about ongoing development capacity.
The repository has only 2 stars, 0 forks, and 1 watcher. Popularity is not decisive, but these figures provide little independent evidence of a broad maintenance community.
Composer build tooling is present, but no security-scanning tools were detected. The missing scanning is a modest transparency and hygiene gap, not evidence that the package is unsafe.
Both workflows were analyzed successfully with no audit findings, and the pull_request_target workflow has no untrusted checkout or script-injection sink. However, both analyzed action references are unpinned, leaving avoidable build-integrity risk.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
hyperf/command Version ~3.2.0 | — | — |
hyperf/support Version ~3.2.0 | — | — |
hyperf/contract Version ~3.2.0 | — | — |
hyperf/tappable Version ~3.2.0 | — | — |
hyperf/stringable Version ~3.2.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.