Clear licensing mismatch and weak workflow pinning add adoption risk. Tests, documentation, and a matching repository provide useful structure, but do not offset the stale release and commit record.
42%
Total Score
0
63
50
This package has only one release, with no release in about two years; that strongly suggests abandonment and leaves no evidence of ongoing maintenance.
The repository recorded zero commits and zero active maintainers in the last three months, reinforcing the long release gap rather than showing active upkeep.
The manifest declares Apache-2.0 while the artifact and repository license files are detected as MIT. A license mismatch creates avoidable legal uncertainty despite the presence of license files.
The repository has no security policy, reducing transparency for reporting and handling vulnerabilities in a framework skeleton with multiple runtime dependencies.
All three analyzed action references are unpinned, and a high-confidence medium-severity finding identifies an archived action in the release workflow. The workflows have no untrusted triggers or dangerous checkout sinks, which limits the risk.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
hyperf/cache Version ~3.1.0 | — | — |
hyperf/config Version ~3.1.0 | — | — |
hyperf/engine Version ^2.10 | — | — |
hyperf/guzzle Version ~3.1.0 | — | — |
hyperf/logger Version ~3.1.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.