The README clearly warns that its Baidu calendar source may break when that interface changes. Tests and a declared MIT license improve transparency, while the package remains pre-1.0.
59%
Total Score
50
100
75
75
The package and repository are owned by the same individual account, and the project is not presented as organization-backed. This is consistent ownership, but it also indicates a narrow backing base.
Only two releases exist, with no release in the last 12 months and the latest published about 2 years and 9 months ago. The repository is not archived, but this long pause is a meaningful maintenance concern.
There are no open issues or pull requests and no recent issue or pull-request activity. This may reflect a small, quiet project, but it provides no evidence of an active support channel.
The repository has 1 star, 0 forks, and 2 watchers, showing very limited adoption. Popularity is supporting evidence only, but it reinforces the limited maintenance-capacity concern.
Composer build tooling is present, but no security-scanning tooling was detected. That is a modest transparency and maintenance gap, not a severe risk by itself.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
hyperf/di Version ~3.1.0 | — | — |
hyperf/cache Version ~3.1.0 | — | — |
hyperf/config Version ~3.1.0 | — | — |
hyperf/command Version ~3.1.0 | — | — |
hyperf/context Version ~3.1.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.