The MIT license and lack of install-time scripts reduce avoidable adoption concerns. The linked project is tiny and its repository name does not match the package, adding uncertainty about provenance.
10%
Total Score
0
30
100
Packagist marks the entire package as abandoned, with no replacement specified. This is a direct warning that maintainers no longer support depending on this release.
The package has had no releases in over six years, despite a prior release cadence of about 22 days. That sustained stoppage strongly indicates abandonment.
The repository recorded zero commits and zero active maintainers over the last three months, consistent with its archived state and lack of ongoing maintenance.
The linked GitHub repository is archived and was last pushed over six years ago. An archived source project is a severe abandonment risk for a dependency.
The linked repository name does not match the package name, and no README mention was available. Organization backing provides some context, but package provenance remains uncertain.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
psr/log Version ^1.0 | — | — |
hyperf/utils Version ~1.1.0 | — | — |
psr/container Version ^1.0 | — | — |
hyperf/contract Version ~1.1.0 | — | — |
psr/http-server-middleware Version ^1.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.