Openswoole core library
68%
Total Score
caution
Usable with caveats: recent maintenance rests on one contributor, with no security policy and an unpinned workflow action.
All three-month commit activity comes from one contributor. Organization backing provides some handoff capacity, but no second active contributor is shown to reduce the immediate concentration risk.
Only one commit was recorded in the last three months, from one active maintainer. The recent code activity is therefore thin and lowers confidence in sustained maintenance.
The repository has no security policy. For a core asynchronous runtime library, that is a transparency and vulnerability-reporting gap not covered by the otherwise healthy release and repository signals.
The sole workflow was fully analyzed with no dangerous sinks or audit findings, but its one action reference is unpinned. That is a minor supply-chain hygiene weakness without evidence of an exploitable workflow path.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
psr/http-message Version ^1.0 || ^2.0 | — | — |
psr/http-server-middleware Version ^1.0.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.