The package has a clear Apache license, tests, and organization-backed ownership. Its small community, absent security policy, and unpinned workflow actions add maintenance and build-integrity concerns.
42%
Total Score
50
100
78
75
The package has had no release in about five years, despite 12 releases overall; this is strong evidence of stalled maintenance for a dependency.
There were zero commits and zero active maintainers in the last three months, consistent with the package's roughly five-year release gap and indicating no current maintenance capacity.
The repository has only 2 stars and 6 forks, indicating a small adoption and review base. Popularity is supporting evidence, but this still modestly increases abandonment risk.
Composer is used for builds, but no security scanning tools were detected. This is a transparency and maintenance gap, though it is less severe than the inactivity evidence.
The repository has no security policy, leaving vulnerability reporting and response expectations unclear for consumers.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
swoft/framework Version ~2.0.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.