The MIT license and matching repository make ownership and reuse clear. Its small, inactive project has limited evidence of ongoing support, so pinning this release is prudent.
58%
Total Score
50
81
75
The package has had no releases in about 1 year 7 months, despite 16 releases clustered at its launch. This is meaningful evidence of stalled maintenance for a library dependency.
Only one registry publishing maintainer is listed, which creates a thin operational base. The linked repository is owned by the same individual, so this is a modest rather than severe concern.
The repository recorded zero commits and zero active maintainers in the last 3 months, reinforcing the release-history evidence of inactivity.
Composer is used for builds, but no security scanning tools are present. That is a transparency and maintenance gap, though it is not evidence of unsafe behavior by itself.
The repository has no security policy, leaving no documented process for reporting or handling vulnerabilities.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
hyperf/di Version ^3.1 | — | — |
hyperf/event Version ^3.1 | — | — |
hyperf/config Version ^3.1 | — | — |
hyperf/server Version ^3.1 | — | — |
hyperf/command Version ^3.1 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.