Regular releases, repository tests, and release notes provide useful maturity signals. Organization backing and a security policy add transparency, but the small public footprint limits confidence.
68%
Total Score
67
100
89
100
The repository recorded zero commits and zero active maintainers in the last 3 months, which is a meaningful maintenance warning despite the recent release history.
There are no open issues or pull requests and no recent issue or pull-request activity; this is not inherently unhealthy, but it offers little evidence of active community review.
The repository has only 1 star, 0 forks, and 2 watchers. Popularity is supporting evidence rather than a verdict, but this small footprint provides little independent adoption signal.
Composer build tooling is present, but no security scanning tools were detected. The repository's security policy partly compensates for this gap, though automated coverage is limited.
Both workflows were analyzed without audit findings, and the pull_request_target workflow has no untrusted checkout or script-injection sink. However, both referenced actions are unpinned, leaving avoidable build-integrity risk.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
hyperf/support Version ~3.2.0 | — | — |
hyperf/contract Version ~3.2.0 | — | — |
hyperf/coroutine Version ~3.2.0 | — | — |
hyperf/coordinator Version ~3.2.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.