The MIT license, repository tests, and organization backing provide a solid maintenance foundation. The package has no install-time scripts and a documented security policy, though workflow references are not pinned. Its recent release history supports continued use despite limited recent commit activity.
74%
Total Score
75
94
100
The repository recorded zero commits and zero active maintainers in the last 3 months. This is a maintenance caution, although the recent release and broader release history provide some compensation.
Composer build tooling is present, but no security-scanning tools were detected, leaving a modest repository hygiene gap.
Both workflows were analyzed successfully with no reported audit findings or untrusted checkout and script-injection sinks. However, both of the two action references are unpinned, which weakens reproducibility and supply-chain hygiene.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
psr/container Version ^1.0 || ^2.0 | — | — |
hyperf/context Version ~3.2.0 | — | — |
hyperf/support Version ~3.2.0 | — | — |
hyperf/contract Version ~3.2.0 | — | — |
hyperf/macroable Version ~3.2.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.