It has a clear license, tests, and a matching repository backed by an organization. The package is small and its workflow has no dangerous audit findings, but dependency updates should be treated cautiously.
58%
Total Score
75
100
88
67
The package has 15 releases since July 2018, but none in the last 12 months, indicating a meaningful maintenance slowdown despite its established history.
There were no commits and no active maintainers in the last 3 months, reinforcing the concern raised by the absence of releases in the last 12 months.
Composer build tooling is present, but no security scanning tools were detected, leaving a modest transparency and maintenance gap.
The repository has no security policy, which makes vulnerability reporting and response expectations less clear.
The only workflow was fully analyzed with no dangerous audit findings, but both of its action references are unpinned, weakening build reproducibility and supply-chain hygiene.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
blackfire/php-sdk Version ^1.16||^2.0 | — | — |
upscale/ext-swoole Version ^4.0||^5.0||^6.0 | — | — |
upscale/ext-openswoole Version ^4.0||^22.0||^25.2 | — | — |
upscale/swoole-reflection Version ^2.0||^3.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.