The repository has no security policy or automated security scanning, while its README, MIT license, and changelog support basic transparency. The package is not deprecated or archived, but its small public footprint limits confidence in long-term support.
63%
Total Score
50
83
75
The repository is owned by an individual account rather than an organization, so there is no visible organizational backing to compensate for the small maintainer or community footprint.
The latest release was in February 2024, with no releases in the last 12 months, so maintenance appears to have slowed substantially. Eight releases over roughly four years provide some history but do not offset the current gap.
The repository has zero stars and forks and one watcher. Popularity is only supporting evidence, but this very small public footprint limits confidence in community support.
Composer is used for builds, but no security-scanning tooling was detected. That is a transparency and maintenance gap for a package with 14 runtime dependencies.
The repository has no security policy, leaving no documented channel or process for reporting vulnerabilities.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
easyswoole/jwt Version >=1.1 | — | — |
easyswoole/log Version >=1.0 | — | — |
easyswoole/orm Version >=1.4 | — | — |
easyswoole/rpc Version 5.x | — | — |
easyswoole/task Version >=1.1 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.