The package is small and focused, with a clear README and a stable v1 release. Maintenance has gone quiet for the last three months, while the release workflow uses unpinned actions and an archived action. Its low adoption and missing security policy add modest transparency concerns.
67%
Total Score
50
100
86
50
There were zero commits and zero active maintainers in the last three months, indicating that maintenance has recently paused. This is a meaningful abandonment risk despite the recent package release.
The repository has 2 stars, 0 forks, and 1 watcher, showing very limited external adoption and review. Small packages can still be healthy, but this provides little independent evidence of maturity.
The repository uses Composer build tooling, which fits the package ecosystem, but no security scanning tools were detected. That leaves an avoidable gap in automated supply-chain checks.
The repository has no security policy. For a component that coordinates distributed ID generation, the absence reduces transparency about reporting and handling operational issues.
The single workflow was fully analyzed and has no untrusted checkout or script-injection findings, but both action references are unpinned and one uses an archived action with high-confidence medium severity. This weakens release reproducibility and supply-chain hygiene.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
hyperf/snowflake Version ^3.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.