Usable with caveats: it has a long release history, recent releases, an active organizational owner, tests, and a current non-archived repository. Recent repository activity is quiet, and its workflows lack explicit token restrictions and security scanning, so review updates carefully before adopting it.
74%
Total Score
67
100
94
80
One of two workflows uses pull_request_target, which can increase workflow risk when handling untrusted pull requests, although no untrusted checkout or script injection was detected.
The repository recorded zero commits and zero active maintainers during the last three months. This is concerning despite the recent release and established release history because current development activity is not visible.
Only one issue is open and there are no open pull requests, but there was no issue or pull-request movement during the last month, providing little evidence of active maintenance through community activity.
Composer build tooling is present, but no security scanning tools are configured, leaving a preventable gap in repository hygiene.
Both analyzed workflows omit top-level GitHub Actions permissions declarations. No workflow requests top-level write access, but explicit least-privilege settings would provide stronger protection.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
hyperf/rpc Version ~3.2.0 | — | — |
hyperf/codec Version ~3.2.0 | — | — |
hyperf/engine Version ^2.0 | — | — |
psr/container Version ^1.0 || ^2.0 | — | — |
hyperf/context Version ~3.2.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.