Package Health

hyperf/pipeline

Hyperf Macroable package which come from illuminate/pipeline

Latest v3.2.0PackagistPackagist

68%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

75

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

93

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

50

Health Score Breakdown

Dangerous workflowscaution

One of two workflows uses pull_request_target, which requires careful handling of untrusted pull requests. No untrusted checkout or script-injection patterns were detected, limiting the concern.

Repo commit activitycaution

The repository recorded zero commits and zero active maintainers over the last three months. This is a meaningful maintenance concern, although the recent registry release and organizational ownership provide some counterevidence.

Repo toolingcaution

Composer build tooling is present, but no security scanning tools were detected. This is a hygiene gap rather than evidence that the package is unsafe.

Token permissionscaution

Both workflows lack top-level token permission declarations. No workflow requests top-level write permissions, but explicit least-privilege settings would provide stronger transparency.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

No maintainer information available.

Direct Dependencies

DependencyLast ReleaseScore
psr/container
Version ^1.0 || ^2.0
—
—
hyperf/macroable
Version ~3.2.0
—
—

Weekly Downloads

Info

Last Published
4 months ago
Created
3 years ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform