The project includes tests, a working README, and a clear Apache-2.0 license. Its maintenance has stopped since July 2024, while the workflows use unpinned actions and one archived action.
58%
Total Score
50
50
75
50
The latest release was July 16, 2024, with no releases in the following 12 months despite the package being established for over three years. That indicates materially reduced maintenance activity.
There were no commits and no active maintainers in the last three months. Combined with the old latest release, this is strong evidence that ongoing maintenance has stopped.
The release declares 35 runtime dependencies, including a broad framework and several project-specific modules. This increases maintenance and transitive-dependency exposure, though it is consistent with a full application skeleton.
Install and update lifecycle scripts run package-management setup actions, adding execution complexity during installation and updates. This is a moderate transparency concern for a project skeleton but not severe on its own.
The repository uses Composer build tooling, but no security-scanning tool was detected. This is a hygiene gap rather than evidence that the package is unsafe.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
maliboot/di Version * | — | — |
hyperf/cache Version ~3.0.0 | — | — |
maliboot/dto Version * | — | — |
hyperf/config Version ~3.0.0 | — | — |
hyperf/guzzle Version ~3.0.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.