A clear README, MIT licensing, release notes, and regular releases make adoption straightforward. Organizational backing and a non-archived repository help, but recent work is concentrated in one contributor and workflow references are unpinned.
72%
Total Score
63
100
100
100
All recent commit activity came from one contributor, creating a concentrated maintenance path; organizational ownership provides some handoff capacity but does not remove the current concentration.
Only one commit was recorded in the last 3 months, indicating limited recent development activity despite the recent release history.
There are 7 open issues and no issue or pull-request activity in the last month, which is a mild sign of limited current responsiveness, though not evidence of abandonment by itself.
Both workflows were analyzed without audit findings, and the pull_request_target workflow has no untrusted checkout or script-injection sink. However, all 2 action references are unpinned, leaving a reproducibility and action-integrity hygiene gap.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
hyperf/codec Version ~3.2.0 | — | — |
hyperf/engine Version ^2.0 | — | — |
hyperf/context Version ~3.2.0 | — | — |
hyperf/support Version ~3.2.0 | — | — |
hyperf/contract Version ~3.2.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.