The contracts of Hyperf.
68%
Total Score
75
100
94
75
One of two analyzed workflows uses pull_request_target, which can increase workflow risk when handling untrusted pull requests. No untrusted checkout or script-injection patterns were detected, so this is a caution rather than a severe risk.
There were no commits and no active maintainers in the last three months. This conflicts with the recent release history and is a meaningful maintenance-risk signal, though it does not yet establish abandonment.
Composer is used as the build tool, but no security scanning tools were detected. The missing scanning is a transparency gap, while the package's small, dependency-light structure limits its practical significance.
Both workflows lack top-level token permissions declarations. No workflow requests top-level write permissions, which reduces the concern, but explicit least-privilege configuration is still missing.
We didn't find any vulnerabilities for this package.
No maintainer information available.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.