The alpha status and absent security policy add uncertainty for a production dependency. Licensing, tests, a clear repository match, and no install scripts are reassuring, but they do not offset the lack of recent project activity.
35%
Total Score
33
50
72
83
Only two releases were published, both in April 2022, with no releases in the last 12 months; this is strong evidence of abandonment risk for a client library.
There were no commits and no active maintainers in the last three months, consistent with a project that has been inactive for years.
Seven runtime dependencies, including the Swoole extension and related client libraries, create a specialized dependency footprint but are consistent with the package's Swoole-focused purpose.
One registry maintainer is consistent with a small user-owned project, but it provides little redundancy when combined with the lack of recent activity.
The repository is owned by an individual user rather than an organization, so the single-maintainer context offers limited demonstrated backing for long-term support.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
psr/log Version ^1.1 | — | — |
monolog/monolog Version ^2.4 | — | — |
easyswoole/http-client Version ^1.5 | — | — |
easyswoole/swoole-ide-helper Version ^1.3 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.