Usable with caveats: the package is clearly backed by a matching organization repository with tests, releases, and a security policy, but maintenance appears stalled. There have been no releases or commits for about 1 year and 9 months, so verify compatibility before adopting it.
62%
Total Score
75
50
81
88
Ten runtime dependencies, including core Hyperf components, create a meaningful compatibility surface for a framework addon, but the dependency list is coherent with the package's stated websocket functionality rather than unusually broad.
The package has a substantial history of 62 releases since April 2021, but it has had no release in about 1 year and 9 months and no releases in the last 12 months. That materially lowers confidence in ongoing maintenance.
The repository recorded zero commits and zero active maintainers in the last three months, consistent with the long release gap and indicating stalled current development.
The repository has only 2 stars and 1 fork, showing a small user base. Popularity is supporting evidence rather than a verdict, but the low adoption provides little external confidence to offset the maintenance gap.
Composer build tooling is present, but no security-scanning tools were detected. The missing scanning is a transparency gap, though it is partly offset by the repository's other security controls.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
hyperf/di Version ~3.1.0 | — | — |
hyperf/event Version ~3.1.0 | — | — |
hyperf/redis Version ~3.1.0 | — | — |
hyperf/signal Version ~3.1.0 | — | — |
hyperf/process Version ~3.1.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.