The package has a clear README, organization backing, and no install-time scripts. Its license signals disagree, there is no security policy or scanning, and the workflow uses an unpinned action.
53%
Total Score
100
100
81
67
The package declares MulanPSL-2.0 and has a license file, but the repository license file was detected as MIT. That mismatch should be clarified before adoption.
The package has had no releases in the last 12 months, with the latest release on December 29, 2023. Its earlier median release interval of about 35 days shows prior activity, but the current pause raises maintenance concerns.
Composer is used as the build tool, but no security scanning tools were detected. This is a transparency and maintenance weakness, not evidence that the package is unsafe.
The repository has no security policy, leaving vulnerability reporting and response expectations undocumented.
The sole workflow uses pull_request_target without an untrusted checkout or script injection, so the trigger is not concerning on its own. However, its one action reference is unpinned, creating a modest workflow reproducibility risk.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
imiphp/imi-swoole Version ~2.1.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.