It has an MIT license, a clear README, repository tests, and no install-time scripts. Maintenance stopped more than five years ago, with no recent commits or releases. The workflow also uses unpinned actions and an archived action, while the repository has no security policy.
38%
Total Score
50
100
72
67
The last release was in July 2021, more than five years ago, and there were no releases in the past 12 months. That is strong evidence of abandonment for a dependency that may need compatibility updates.
There were zero commits and zero active maintainers in the past three months, consistent with more than five years without a release and indicating no current maintenance capacity.
The repository has only 2 stars, 0 forks, and 1 watcher. Low popularity is supporting evidence of limited adoption, not a standalone reason to reject the package.
Composer is used as the build tool, but no security scanning tools were detected. For a small, inactive package this is a meaningful transparency and maintenance gap.
The linked repository is not archived, but its last push was in July 2021. The active repository status therefore does not compensate for the observed inactivity.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
hyperf/di Version ~2.2.0 | — | — |
hyperf/framework Version ~2.2.0 | — | — |
hyperf/http-server Version ~2.2.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.