The package includes tests and a matching Apache license, but its single release and zero recent commits leave maintenance uncertain. All five workflow actions are unpinned, with no security policy or scanning; adopt only if you can accept ownership risk.
38%
Total Score
50
90
50
This is the package's only release, published 643 days ago, with no releases in the last 12 months. That leaves little evidence of ongoing maintenance for a framework dependency.
The repository recorded 0 commits and 0 active maintainers in the last 3 months. Combined with the one-release history, this is a substantial abandonment concern.
The repository has no security policy and no security scanning tools were reported. For a framework intended to run in applications, this weakens vulnerability reporting and maintenance transparency.
Both workflows were fully analyzed with no dangerous triggers, sinks, or audit findings, and no top-level write permissions. However, all 5 of 5 action references are unpinned, leaving avoidable build reproducibility and action-substitution risk.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
swoft-fork/aop Version ~2.1.0 | — | — |
swoft-fork/log Version ~2.1.0 | — | — |
swoft-fork/bean Version ~2.1.0 | — | — |
swoft-fork/error Version ~2.1.0 | — | — |
swoft-fork/event Version ~2.1.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.