The repository is still active in structure, licensed, tested, and backed by an organization. However, no registry releases or commits have appeared for over two years, and every workflow reference is unpinned with one archived action.
58%
Total Score
50
100
83
75
The package has made no releases in the last 12 months, and its latest release was over two years ago despite a 68-day median interval historically. This is a substantial abandonment concern for a framework dependency.
The repository recorded zero commits and zero active maintainers in the last three months. Combined with the old latest release, this materially raises the risk that problems will not be addressed.
The package runs post-autoload-dump and post-root-package-install scripts. Install-time scripts deserve extra review because they execute during dependency setup, although this signal alone does not show that they are unsafe or poorly maintained.
There were no new or closed issues or pull requests in the last month, while six issues and two pull requests remain open. This reinforces the evidence of a currently quiet project.
Composer build tooling is present, but no security-scanning tool was detected. This is a transparency and maintenance gap, though it is less severe because a security policy exists and the package has an established test setup.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
hyperf/di Version 3.1.* | — | — |
hyperf/phar Version 3.1.* | — | — |
hyperf/cache Version 3.1.* | — | — |
hyperf/event Version 3.1.* | — | — |
hyperf/utils Version 3.1.* | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.