Package Health

goletter/hyperf-casbin

The package includes tests, a readable README, and a matching Apache-2.0 license. Its 17 runtime dependencies and single-contributor history make long-term maintenance less certain.

Latest v1.0.0PackagistPackagist

61%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

60

Dependencies
Dependencies
Evaluates the health and security of package dependencies

50

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

88

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

83

Health Score Breakdown

Dependency profilecaution

Seventeen runtime dependencies, including several Hyperf components and extensions such as Redis and Swoole, create a relatively broad compatibility and maintenance surface.

Maintainerscaution

Only one registry publishing maintainer is listed. Because the repository is user-owned rather than organization-owned, there is no provided project-backing evidence to offset this concentration.

Project backingcaution

The registry namespace and repository owner match, and the owner is an individual user. This supports package identity but offers no organizational backing to offset the concentrated maintainer base.

Release historycaution

The package is only 56 days old and has one release, so there is not yet enough release history to demonstrate sustained maintenance.

Repo bus factorcaution

All recent commits came from one contributor, creating a narrow maintenance base. The user-owned project backing does not provide evidence of an organization that could hand maintenance off.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

goletter

Direct Dependencies

DependencyLast ReleaseScore
hyperf/cache
Version ~3.1
hyperf/redis
Version ~3.1
casbin/casbin
Version ~3.21
hyperf/config
Version ~3.1
hyperf/logger
Version ~3.1

Weekly Downloads

Info

Last Published
1 month ago
Created
1 month ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform