There have been no commits or releases for about 21 months, and the README says active maintenance is not guaranteed. Apache-2.0 licensing, tests, and a non-archived repository provide useful safeguards, but this release needs an owner willing to maintain it.
40%
Total Score
0
70
50
This package has only one release, published about 21 months ago, with no releases in the last 12 months. That gives little evidence of an established maintenance cycle.
The repository recorded zero commits and zero active maintainers over the last three months, consistent with the package's explicit warning that active maintenance is not guaranteed.
The repository has zero stars, forks, and watchers, providing no supporting evidence of broad community review or adoption. Popularity is only supporting evidence, so this reinforces rather than determines the maintenance concern.
The repository has no security policy, leaving reporting and response expectations unclear. This is a meaningful transparency gap for a server component, though it is not evidence of a vulnerability.
Both workflows were analyzed without dangerous triggers, untrusted checkouts, or audit findings. However, all five action references are unpinned, leaving build inputs less reproducible and exposed to action changes.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
swoft-fork/rpc Version ~2.1.0 | — | — |
swoft-fork/framework Version ~2.1.0 | — | — |
swoft-fork/connection-pool Version ~2.1.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.