The package has a clear README, tests in the repository, and a matching source project. Its narrow release history and absent recent development leave substantial abandonment risk for a production dependency.
38%
Total Score
25
100
72
88
Only two releases exist, both from June 2020, with no releases in the last six years. This is strong evidence of an inactive package despite its stable version.
There were zero commits and zero active maintainers in the last three months, consistent with the repository having been inactive since June 2020. This materially increases abandonment risk.
The repository is owned by an individual account rather than an organization, so there is no organizational backing signal to offset the thin maintenance history.
The repository has zero stars, forks, and watchers. Low popularity is supporting evidence rather than a verdict, but it provides no community signal to compensate for the inactive maintenance record.
Composer is used for builds, but no security scanning tools are present. The missing scanning is a hygiene gap, while the build tooling is appropriate for this package.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
hyperf/di Version ~2.0.0 | — | — |
hyperf/utils Version ~2.0.0 | — | — |
hyperf/config Version ~2.0.0 | — | — |
hyperf/guzzle Version ~2.0.0 | — | — |
hyperf/contract Version ~2.0.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.