Package Health

on1kel/hyperf-nestedset

The package is young but has released seven times in about nine months, with a stable v1.0.6. Its single-star repository has no security policy or scanning, and the declared MIT license conflicts with the detected Apache-2.0 file.

Latest v1.0.6PackagistPackagist

68%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

100

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

83

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

83

Health Score Breakdown

Licensecaution

The manifest declares MIT, but the detected license text is Apache-2.0 despite license files being present in both the artifact and repository. The mismatch creates a real licensing clarity concern.

Repo popularitycaution

The repository has one star, no forks, and no watchers. This is limited adoption evidence, although popularity alone does not establish poor maintenance for a small package.

Repo toolingcaution

Composer build tooling is present, but no security scanning tools were detected. That leaves a transparency and maintenance-hygiene gap.

Security policycaution

The repository has no security policy. This does not show a vulnerability, but it gives users little guidance for reporting or handling security issues.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

No maintainer information available.

Direct Dependencies

DependencyLast ReleaseScore
ramsey/uuid
Version ^4.7
hyperf/event
Version ^3.1
hyperf/database
Version ^3.1
hyperf/db-connection
Version ^3.1

Weekly Downloads

Info

Last Published
6 months ago
Created
9 months ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform