The stable version line, long release history, repository tests, and security policy add useful reassurance. Maintenance is currently concentrated in one contributor, and workflow actions are not pinned.
76%
Total Score
67
93
100
All recent commit activity came from one contributor, leaving maintenance dependent on a single active individual; organization ownership provides some capacity for handoff but does not remove the concentration concern.
Only 1 commit was recorded in the last 3 months, indicating limited recent development activity despite the recent release history.
Composer build tooling is present, but no security scanning tools were detected; this is a modest transparency and hygiene gap rather than evidence of unsafe code.
Both workflows were analyzed successfully and no audit findings or untrusted-checkout or script-injection sinks were reported. However, both action references are unpinned, so their contents can change without a repository commit.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
hyperf/engine Version ^2.0 | — | — |
psr/container Version ^1.0 || ^2.0 | — | — |
hyperf/context Version ~3.2.0 | — | — |
hyperf/support Version ~3.2.0 | — | — |
hyperf/contract Version ~3.2.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.