Package Health

hyperf/swoole-tracker

The package has a clear MIT license, no install-time scripts, and a security policy. Organization ownership and a matching repository provide useful provenance, but an archived workflow action and absent security scanning add maintenance concerns.

Latest v3.1.0-rc.4PackagistPackagist

54%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

50

Dependencies
Dependencies
Evaluates the health and security of package dependencies

100

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

71

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

83

Health Score Breakdown

Release historydanger

The package has 28 releases over about seven years, but it has had no release in about three years. That materially raises abandonment and compatibility risk.

Repo commit activitydanger

There were zero commits and zero active maintainers in the last three months, consistent with the roughly three-year release gap and indicating weak current maintenance.

Repo toolingcaution

Composer is used for the build, but no security-scanning tool is configured. This is a hygiene gap, not evidence that the package is unsafe by itself.

Version stabilitycaution

The assessed version is v3.1.0-rc.4, a prerelease, and recent releases have a 45% prerelease share. Consumers should expect less release stability than from a final version.

Workflow auditcaution

Both workflows were analyzed successfully, with no untrusted checkout or script-injection findings. However, all three action uses are unpinned and one high-confidence medium-severity finding uses an archived action, weakening workflow reproducibility and maintenance hygiene.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

No maintainer information available.

Direct Dependencies

DependencyLast ReleaseScore
hyperf/utils
Version ~3.1.0
—
—
psr/container
Version ^1.0|^2.0
—
—
hyperf/support
Version ~3.1.0
—
—
hyperf/contract
Version ~3.1.0
—
—
psr/http-server-middleware
Version ^1.0
—
—

Weekly Downloads

Info

Last Published
3 years ago
Created
6 years ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform