The repository includes substantial tests, release notes, a security policy, and recent work. Workflow references are not pinned, and the package remains an early beta with limited adoption.
65%
Total Score
75
50
78
75
Eight runtime dependencies, including several closely related Hibla components, increase the dependency surface for an early package. The signal provides no evidence that these dependencies are unsafe or unmaintained, so this is a limited concern.
The package is only 93 days old with four releases, all within the last 12 months and a median interval of about 23 hours. This shows active early development but provides limited evidence of long-term stability.
One contributor made all six commits in the last three months. Organization ownership provides some handoff capacity, but no second active contributor is shown, leaving maintenance dependent on one person in practice.
The repository recorded six commits in the last three months, showing recent maintenance. All activity comes from one contributor, which limits the evidence of broader maintenance capacity.
The repository has one star, no forks, and no watchers. This is weak adoption evidence, although popularity is only supporting evidence and does not outweigh the demonstrated project activity.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
hiblaphp/sql Version ^1.0 | — | — |
hiblaphp/async Version ^1.0 | — | — |
hiblaphp/cache Version ^1.0 | — | — |
hiblaphp/stream Version ^1.0 | — | — |
hiblaphp/promise Version ^1.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.