The MIT license, matching repository, and organization ownership provide clear provenance. The four-file library has no README, which makes integration harder, and no recent security scanning is reported.
12%
Total Score
50
42
100
Packagist marks the entire package as abandoned, with no replacement specified. This is a direct warning against taking a new dependency on the package.
The latest release was published over 6 years ago, with no releases in the last 12 months. This strongly indicates abandonment rather than an actively maintained stable release.
The repository recorded zero commits and zero active maintainers in the last 3 months, providing no evidence of ongoing maintenance.
The linked repository is archived and was last pushed over 6 years ago, indicating the source project is no longer maintained.
The artifact has no README, which is a minor integration gap for a library consumers must configure. Missing tests and changelog files are normal for a published artifact and are not concerns here.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
psr/log Version ^1.0 | — | — |
hyperf/utils Version ~1.1.0 | — | — |
psr/container Version ^1.0 | — | — |
hyperf/contract Version ~1.1.0 | — | — |
psr/http-server-middleware Version ^1.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.