Package Health

goletter/hyperf-docs

This release is usable but still relatively immature. It has a valid MIT declaration, a focused 24-file implementation, no install-time lifecycle scripts, stable versioning, an active non-archived repository, and the repository clearly matches the package. However, it is only 43 days old with two releases, has no tests or changelog, no observed commit activity or active maintainers in the last 3 months, no security scanning or security policy, and no popularity or issue history to provide additional confidence. The zero recent-activity result may partly reflect the package's young age, but the combination of limited validation and a single publisher makes this a package to adopt cautiously and monitor.

Latest v1.0.3PackagistPackagist

62%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

50

Dependencies
Dependencies
Evaluates the health and security of package dependencies

50

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

78

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

88

Health Score Breakdown

Dependency profilecaution

Six runtime dependencies are declared, including external API clients and Hyperf framework components. This is a meaningful but not unusually broad dependency surface; the absence of development dependencies also aligns with the lack of packaged test infrastructure.

Maintainerscaution

Only one registry account has publish access. The linked repository is user-owned rather than organization-owned, so there is no organizational backing signal to compensate for this thin publisher base.

Package scaffoldingcaution

A substantial README is present, but neither the artifact nor the repository contains tests or a changelog. For an integration package handling Google and Tencent APIs, the absence of visible tests reduces maintenance and regression confidence.

Project backingcaution

The package repository is owned by the same user identity as the package publisher, providing direct ownership alignment. It is not organization-backed, so broader continuity support cannot be inferred.

Release historycaution

The package is only 43 days old and has two releases, with a median interval of about 43 days. This is too limited a history to establish long-term maintenance reliability, though it is not evidence of abandonment by itself.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

goletter

Direct Dependencies

DependencyLast ReleaseScore
hyperf/di
Version ~3.1.0
hyperf/command
Version ~3.1.0
hyperf/contract
Version ~3.1.0
google/apiclient
Version ^2.19
guzzlehttp/guzzle
Version ^7.0

Weekly Downloads

Info

Last Published
18 days ago
Created
2 months ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform