The package has a long release history, organization backing, tests in the repository, and a current security policy. Recent repository activity is quiet, and both workflow action references are unpinned, leaving maintenance and build-integrity concerns.
67%
Total Score
67
50
89
100
Thirteen runtime dependencies create a relatively broad dependency surface for a component, though the listed dependencies are consistent with its framework integration role.
The repository recorded zero commits and zero active maintainers in the last 3 months, which is a meaningful sign of currently quiet maintenance despite the recent release history.
There is one open issue and no issue or pull-request activity in the last month, reinforcing the picture of limited recent repository activity.
The repository has only 1 star and 0 forks, providing little community validation; this is supporting evidence rather than a decisive health problem.
Composer build tooling is present and the repository has a SECURITY.md policy, but no security scanning tools were detected, leaving a modest process gap.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
hyperf/codec Version ~3.2.0 | — | — |
psr/container Version ^1.0 || ^2.0 | — | — |
hyperf/context Version ~3.2.0 | — | — |
hyperf/support Version ~3.2.0 | — | — |
swow/psr7-plus Version ^1.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.