The package includes tests, a usable README, Composer tooling, Dependabot, and organizational ownership. Its workflows also use five unpinned actions and one archived action, increasing maintenance and build-integrity concerns.
46%
Total Score
0
75
The package has only two releases, with the latest on November 9, 2021 and none in the last 12 months. This long release gap is a substantial abandonment concern for a production dependency.
The repository recorded zero commits and zero active maintainers in the last 3 months, and its last push was in January 2023. The inactive source confirms that maintenance has materially slowed.
All five analyzed action references are unpinned, and the audit found one high-confidence medium-severity archived action. There are no untrusted checkouts or script injections, but the workflow supply-chain hygiene remains weak.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
hyperf/di Version 2.2.* | — | — |
hyperf/nsq Version 2.2.* | — | — |
hyperf/amqp Version 2.2.* | — | — |
hyperf/pool Version 2.2.* | — | — |
hyperf/cache Version 2.2.* | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.