Tests are maintained in the repository, and the project has an organization owner and a security policy. Its workflows use unpinned actions, so updates should be checked before relying on its automation.
68%
Total Score
75
94
100
The repository recorded no commits and had no active maintainers in the three months before collection. Recent registry releases partly compensate, but the absence of recent source activity raises maintenance risk.
Composer is used for builds, but no security-scanning tools were detected. This is a modest transparency and assurance gap rather than evidence of unsafe code.
Both workflows were analyzed successfully and no audit findings or untrusted checkouts were reported. However, both actions are unpinned, leaving their exact revisions mutable; the pull_request_target trigger is not concerning here because no dangerous sink was found.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
hyperf/context Version ~3.2.0 | — | — |
hyperf/support Version ~3.2.0 | — | — |
hyperf/database Version ~3.2.0 | — | — |
hyperf/collection Version ~3.2.0 | — | — |
hyperf/stringable Version ~3.2.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.