The MIT license, README, and release notes provide useful transparency for adoption. The one-person, low-visibility project lacks security scanning and a security policy, leaving less evidence for long-term support.
59%
Total Score
50
100
83
83
The repository is owned by an individual GitHub user rather than an organization, so the single registry maintainer reflects a genuinely thin visible ownership base.
The package has only five releases and none in the last 12 months; its latest release was over two years ago, which raises maintenance and abandonment concerns.
There were zero commits and zero active maintainers during the last three months, consistent with no observed development since February 2024 and a meaningful abandonment risk.
The repository has zero stars and forks and only one watcher. Low popularity is supporting evidence of limited adoption, but it is not decisive for a small, focused package.
Composer is used for builds, but no security-scanning tools were detected. That weakens evidence of ongoing supply-chain hygiene without making the release unfit by itself.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
hyperf/di Version ~3.0.0 | — | — |
hyperf/config Version ~3.0.0 | — | — |
hyperf/command Version ~3.0.0 | — | — |
hyperf/context Version ~3.0.16 | — | — |
hyperf/support Version ~3.0.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.