The repository is very small and lacks security policy and security scanning. The stable 2.0.0 release is recent, but the project has only two releases across about two and a half years and no commits in the last three months.
53%
Total Score
50
60
50
The package declares no license, contains no license file, and the repository has no license file, leaving consumers without clear permission to use or redistribute it.
The artifact and repository contain a small, matching six-file tree focused on the package implementation, which is consistent with a narrowly scoped package but provides little evidence of project maturity.
Only two releases have been published across about two and a half years, with one release in the last 12 months; this suggests limited maturity and an uncertain maintenance cadence.
There were no commits and no active maintainers in the last three months. Although a recent release shows some activity, the current absence of development activity raises maintenance risk.
The repository has zero stars and forks and only one watcher. Popularity is not decisive for a small package, but these counters provide no supporting evidence of broad review or adoption.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
verdient/token Version ^0.1 | — | — |
hyperf/contract Version ^3.1 | — | — |
psr/http-message Version ^2.0 | — | — |
verdient/hyperf3-access-control Version ^2.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.