Elasticsearch client for hyperf
62%
Total Score
75
88
100
No commits and no active maintainers were recorded in the last three months, which weakens evidence of ongoing maintenance despite the recent release.
Seven stars and seven forks indicate a small project footprint. Popularity is supporting evidence only, so this modest reach lowers confidence in community support rather than making the package unsafe by itself.
Composer is used for builds, but no security scanning tools were detected, leaving a repository hygiene gap.
Both workflows were analyzed successfully with no audit findings or dangerous untrusted checkouts, but both use actions without pinning. The pull_request_target trigger is ordinary here because no corresponding sink was detected.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
hyperf/guzzle Version ~3.2.0 | — | — |
elasticsearch/elasticsearch Version ^8.0 || ^9.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.