The package is licensed, backed by an organization, and has a long release history. Its workflows use unpinned actions, leaving avoidable update and provenance risk.
68%
Total Score
75
94
100
The repository recorded zero commits and zero active maintainers during the last three months, which raises a maintenance concern despite the recent release and long release history.
Composer is used for builds, but no security scanning tools were detected, leaving a modest transparency and maintenance gap.
Both workflows were fully analyzed with no reported audit findings or untrusted checkouts, but both of the two action references are unpinned, creating avoidable supply-chain hygiene risk. The pull_request_target trigger is not concerning on its own because no matching sink was found.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
hyperf/codec Version ~3.2.0 | — | — |
psr/container Version ^1.0 || ^2.0 | — | — |
hyperf/context Version ~3.2.0 | — | — |
hyperf/support Version ~3.2.0 | — | — |
hyperf/contract Version ~3.2.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.