Usable with caveats: it is a clearly identified, licensed package with a practical README and no deprecation or install-time scripts. However, it has only one release, no visible security policy or scanning, and no community traction, so long-term maintenance is unproven.
64%
Total Score
75
100
78
90
One registry account has publish access. For an individually owned package this is not inherently unsafe, but it creates a narrow publishing base if that maintainer becomes inactive.
This is a young package with one release, first published 105 days ago and no subsequent release yet. That does not prove abandonment, but it leaves maintenance continuity unestablished.
The repository has zero stars, forks, and watchers. Popularity is only supporting evidence, but the absence of any adoption signal adds uncertainty for a young package.
Composer is used as the build tool, which fits the PHP package, but no security scanning tooling is present. This is a transparency and process gap rather than evidence that the package is unsafe.
The linked repository is not archived, but its last push was on the same day as the only release, so there is not yet evidence of continuing source maintenance.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
topthink/framework Version ^6.0|^8.0 | — | — |
topthink/think-swoole Version ^4.1 | — | — |
php-amqplib/php-amqplib Version ^3.7 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.