This release is usable but still relatively immature. It has a valid MIT declaration, a focused 24-file implementation, no install-time lifecycle scripts, stable versioning, an active non-archived repository, and the repository clearly matches the package. However, it is only 43 days old with two releases, has no tests or changelog, no observed commit activity or active maintainers in the last 3 months, no security scanning or security policy, and no popularity or issue history to provide additional confidence. The zero recent-activity result may partly reflect the package's young age, but the combination of limited validation and a single publisher makes this a package to adopt cautiously and monitor.
62%
Total Score
50
50
78
88
Six runtime dependencies are declared, including external API clients and Hyperf framework components. This is a meaningful but not unusually broad dependency surface; the absence of development dependencies also aligns with the lack of packaged test infrastructure.
Only one registry account has publish access. The linked repository is user-owned rather than organization-owned, so there is no organizational backing signal to compensate for this thin publisher base.
A substantial README is present, but neither the artifact nor the repository contains tests or a changelog. For an integration package handling Google and Tencent APIs, the absence of visible tests reduces maintenance and regression confidence.
The package repository is owned by the same user identity as the package publisher, providing direct ownership alignment. It is not organization-backed, so broader continuity support cannot be inferred.
The package is only 43 days old and has two releases, with a median interval of about 43 days. This is too limited a history to establish long-term maintenance reliability, though it is not evidence of abandonment by itself.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
hyperf/di Version ~3.1.0 | — | — |
hyperf/command Version ~3.1.0 | — | — |
hyperf/contract Version ~3.1.0 | — | — |
google/apiclient Version ^2.19 | — | — |
guzzlehttp/guzzle Version ^7.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.