The package remains an early-stage v0.0.2 project with no releases in over three years and no recent commits. Documentation, tests, licensing, and a matching organization-owned repository are solid, but the long maintenance gap makes adoption a liability.
48%
Total Score
50
100
75
50
Only two releases were published, both within about one day in May 2023, and there have been no releases in the last three years. This is strong evidence of stalled maintenance for a package still at an early version.
The repository recorded zero commits and zero active maintainers in the last three months. Combined with the old latest release, this indicates no observable current maintenance.
The package uses a post-autoload-dump install lifecycle script. This adds execution during installation and merits awareness, but the signal alone does not show unsafe behavior or make the release unfit.
The linked repository has no security policy. This weakens vulnerability-reporting transparency, although the documented code, tests, and active organization ownership provide some compensating project structure.
The assessed release is v0.0.2 and the package has not reached a stable major version. That is consistent with the README's early-stage status and increases compatibility and maturity risk.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
openswoole/core Version 22.1.2 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.