A small user base and no security scanning leave less evidence for ongoing support. The package includes tests, a clear README, and a declared license, but its install scripts deserve care when adopting it.
38%
Total Score
0
78
50
The latest release was in October 2020, with no releases in the last 12 months. That long pause is strong evidence of abandonment risk for a dependency.
The repository recorded zero commits and zero active maintainers in the last three months. This provides no evidence of current maintenance capacity.
The package runs four Composer lifecycle scripts, including install and update hooks. These are common in framework scaffolding but increase the actions to review before installation.
The repository has 0 stars, 0 forks, and 1 watcher, so there is little visible community adoption to compensate for the stale release history.
Composer is used as the build tool, which is appropriate, but no security scanning tools were detected. That leaves fewer automated checks supporting release hygiene.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
hyperf/cache Version ~2.0.0 | — | — |
hyperf/redis Version ~2.0.0 | — | — |
hyperf/config Version ~2.0.0 | — | — |
hyperf/guzzle Version ~2.0.0 | — | — |
hyperf/logger Version ~2.0.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.