Package Health

ilovintit/hyperf-skeleton

Clear licensing mismatch and weak workflow pinning add adoption risk. Tests, documentation, and a matching repository provide useful structure, but do not offset the stale release and commit record.

Latest v3.1.12PackagistPackagist

42%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

0

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

63

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

50

Health Score Breakdown

Release historydanger

This package has only one release, with no release in about two years; that strongly suggests abandonment and leaves no evidence of ongoing maintenance.

Repo commit activitydanger

The repository recorded zero commits and zero active maintainers in the last three months, reinforcing the long release gap rather than showing active upkeep.

Licensecaution

The manifest declares Apache-2.0 while the artifact and repository license files are detected as MIT. A license mismatch creates avoidable legal uncertainty despite the presence of license files.

Security policycaution

The repository has no security policy, reducing transparency for reporting and handling vulnerabilities in a framework skeleton with multiple runtime dependencies.

Workflow auditcaution

All three analyzed action references are unpinned, and a high-confidence medium-severity finding identifies an archived action in the release workflow. The workflows have no untrusted triggers or dangerous checkout sinks, which limits the risk.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

No maintainer information available.

Direct Dependencies

DependencyLast ReleaseScore
hyperf/cache
Version ~3.1.0
hyperf/config
Version ~3.1.0
hyperf/engine
Version ^2.10
hyperf/guzzle
Version ~3.1.0
hyperf/logger
Version ~3.1.0

Weekly Downloads

Info

Last Published
2 years ago
Created
2 years ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform