Its long release history, recent version release, repository tests, and organization backing support continued use. The missing security scanning and limited recent repository activity warrant keeping the dependency pinned and monitored.
68%
Total Score
67
100
94
100
There were no commits and no active maintainers in the last three months, which weakens evidence of ongoing maintenance despite the recent release.
Only one issue is open and there are no recent issue or pull-request changes; this is a small maintenance concern, though the low issue volume may also reflect a focused package.
Composer build tooling is present, but no security scanning tools are configured, leaving a repository hygiene gap.
Both workflows were fully analyzed with no audit findings or untrusted checkouts; however, both of the two action references are unpinned, reducing build reproducibility and supply-chain protection.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
hyperf/context Version ~3.2.0 | — | — |
hyperf/contract Version ~3.2.0 | — | — |
hyperf/coroutine Version ~3.2.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.