Documentation and packaging are straightforward, with repository tests and a clear MIT license. Maintenance has been quiet for roughly six months, while all four workflow actions are unpinned and one uses an archived action; no security policy is present.
68%
Total Score
50
100
50
There were no commits and no active maintainers in the last 3 months, which is a maintenance concern, although the package had a recent release and repository push earlier in the year.
The repository has no security policy. This weakens transparency for reporting and handling vulnerabilities, with no provided compensating security process.
Both workflows were analyzed without trigger or untrusted-checkout sinks, but all 4 action references are unpinned and a high-confidence medium-severity finding identifies an archived action in the release workflow.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
hyperf/di Version ^3.0 | — | — |
hyperf/event Version ^3.0 | — | — |
hyperf/logger Version ^3.0 | — | — |
hyperf/rpc-client Version ^3.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.