MIT licensing, organization backing, and a long release history provide solid foundations. The recent release and repository tests help, but maintenance activity and workflow pinning need closer attention.
70%
Total Score
75
100
75
The repository recorded zero commits and zero active maintainers in the last three months, a maintenance warning, although the recent release shows the project has not clearly been abandoned.
Both analyzed workflows use unpinned actions, reducing build reproducibility and making action changes harder to control. The pull_request_target workflow has no untrusted checkout or script-injection findings, and the audit completed successfully.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
hyperf/engine Version ^2.0 | — | — |
psr/container Version ^1.0 || ^2.0 | — | — |
hyperf/context Version ~3.2.0 | — | — |
hyperf/support Version ~3.2.0 | — | — |
hyperf/contract Version ~3.2.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.