It has a clear license, tests, release notes, and no install-time scripts. The organization-backed repository is not archived, but the available evidence offers little reassurance for ongoing support.
45%
Total Score
50
100
78
83
The package has had no release in over six years; its eight-release history shows an earlier cadence but no recent maintenance. This is a substantial abandonment concern for a dependency.
There were zero commits and zero active maintainers in the last three months, consistent with the release history and indicating no observed current development.
The repository has only 6 stars and 6 forks, so there is limited external adoption evidence. Popularity is supporting evidence rather than a decisive health measure.
Composer build tooling is present, but no security-scanning tools were detected. This is a modest transparency and maintenance gap, not evidence of unfitness by itself.
No security policy was found, leaving vulnerability-reporting expectations unclear. This is a hygiene gap, partly offset by the repository's organization backing.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
swoft/swlib Version ~2.0.0 | — | — |
swoft/stdlib Version ~2.0.0 | — | — |
swoft/serialize Version ~2.0.0 | — | — |
psr/simple-cache Version ^1.0.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.