The package includes tests, a usable README, and an MIT license declaration. Its repository has no security policy or security-scanning tooling, leaving limited evidence of ongoing oversight.
61%
Total Score
50
100
83
75
The source repository is owned by an individual account rather than an organization. Combined with the small release and inactive commit record, this provides limited visible backing.
This is a young package, released only once about three and a half months ago. That limits evidence of sustained maintenance, though the short history alone does not indicate abandonment.
The repository recorded zero commits and zero active maintainers in the last three months. For a package with only one release, this leaves maintenance continuity unproven and raises abandonment risk.
The repository has zero stars, forks, and watchers. Popularity is only supporting evidence, but the absence of any community signal reinforces the limited maturity evidence.
Composer build tooling is present, but no security-scanning tools are reported. This is a modest oversight gap rather than evidence that the package is unsafe.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
hyperf/config Version ~3.1.0 | — | — |
hyperf/guzzle Version ^3.1 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.