The release has no license and offers little consumer documentation or testing evidence. Its small, matching repository and stable version help, but the project has not demonstrated sustained maintenance yet.
52%
Total Score
50
75
No declared license, license file, or repository license file was detected. This creates a concrete legal and transparency concern for dependency adoption.
The artifact has no README, tests, or changelog. Missing tests and changelog are normal for published artifacts, but the absent README matters for a small library that consumers must integrate.
This package has only one release, published 211 days ago, so there is not enough release history to establish mature maintenance. Its age is still relatively short, which limits how strongly this should be penalized.
There were zero commits and zero active maintainers in the last 3 months, despite the package being more than six months old. This leaves ongoing maintenance capacity unproven.
Composer build tooling is present, but no security scanning tooling was detected. That is a hygiene gap rather than evidence that the package is unsafe.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
hyperf/config Version ^3.1 | — | — |
psr/container Version ^2.0 | — | — |
hyperf/context Version ^3.1 | — | — |
hyperf/support Version ^3.1 | — | — |
hyperf/contract Version ^3.1 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.