The repository has recent commits and tests, but all recent work comes from one person and no security policy is published. The stable MIT release and clear package documentation provide useful safeguards.
42%
Total Score
75
83
75
Packagist marks the entire package as abandoned and names the same package as its replacement, creating a serious adoption and support risk despite the active repository.
All 4 recent commits came from one contributor, leaving maintenance dependent on a single person and increasing continuity risk.
The repository has no published security policy, leaving vulnerability-reporting and response expectations unclear for a package handling cache and rate-limiting behavior.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
hyperf/di Version ^3.1 | — | — |
hyperf/cache Version ^3.1 | — | — |
hyperf/redis Version ^3.1 | — | — |
hyperf/support Version ^3.1 | — | — |
hyperf/tappable Version ^3.1 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.