This component provides features added short functions.
68%
Total Score
75
100
86
67
One of two workflows uses pull_request_target, which can increase CI exposure if untrusted pull-request data is handled unsafely. No untrusted checkout or script-injection patterns were detected, limiting the concern.
The artifact is very small and lacks a README, tests, and changelog, which limits consumer guidance and visible project validation. A GitHub release with notes for this exact version provides some documentation of the change.
The repository recorded zero commits and zero active maintainers in the last three months. This is concerning for maintenance continuity, although the recent release provides limited compensating evidence.
Composer build tooling is present, but no security scanning tools were detected. For a small PHP package this is a hygiene gap rather than evidence that the release is unfit.
Neither workflow declares top-level token permissions. Although no workflow requests explicit write access, the missing declarations reduce CI privilege transparency.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
hyperf/coroutine Version ~3.2.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.