The package is licensed, documented, and backed by an organization with repository tests and a recent release. Its seven stars, no commits in the last three months, and unpinned workflow actions warrant maintenance and build-integrity caution.
68%
Total Score
83
50
89
100
The package declares 17 runtime dependencies, creating a relatively broad dependency surface for a focused RPC component and adding some maintenance complexity.
There were no commits and no active maintainers in the last three months. This is concerning for ongoing maintenance, although the package had a release during that period.
The repository has only 7 stars and 2 forks. Popularity is supporting evidence rather than a verdict, but these low figures provide limited evidence of broad community adoption.
Composer build tooling is present, but no security-scanning tools were detected, leaving a modest repository hygiene gap.
Both workflows were analyzed successfully with no audit findings or untrusted checkouts, and the pull_request_target trigger has no detected sink. However, all two action references are unpinned, reducing build reproducibility.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
hyperf/rpc Version ~3.2.0 | — | — |
hyperf/codec Version ~3.2.0 | — | — |
hyperf/server Version ~3.2.0 | — | — |
hyperf/context Version ~3.2.0 | — | — |
hyperf/support Version ~3.2.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.