Its broad 30-package runtime dependency set increases compatibility and upkeep burden, while the repository has no security policy. MIT licensing and a published release note improve transparency but do not offset the maintenance gap.
40%
Total Score
25
50
86
75
The package has had no releases in roughly 3 years and 11 months, despite 43 releases overall. This is strong evidence of abandonment risk for a framework extension.
The repository recorded zero commits and zero active maintainers during the last 3 months, consistent with the long release gap and leaving current maintenance capacity unproven.
The release declares 30 runtime dependencies, including framework, database, cloud, image, and messaging integrations. This broad surface increases compatibility and upkeep demands when maintenance slows.
Only one registry publishing account is listed. The linked repository is user-owned rather than organization-backed, so there is little visible publishing redundancy.
The linked repository has no security policy, leaving no documented channel or process for reporting vulnerabilities. The absence is a transparency gap, though it is not evidence of maliciousness.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
ramsey/uuid Version ^4.0 | — | — |
hyperf/cache Version ~2.2.0 | — | — |
hyperf/redis Version ~2.2.0 | — | — |
doctrine/dbal Version ^3.0 | — | — |
hyperf/config Version ~2.2.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.