The replacement package should be preferred for new projects. The repository is active but has only one recent contributor and no security policy, so maintenance capacity remains limited.
18%
Total Score
50
75
83
Packagist marks the entire package as abandoned and identifies wenber-yu/hyperf-options as its replacement. This is a severe adoption risk even though the repository still shows recent activity.
The package has four releases since May 2021, with no releases in the last 12 months and the latest release in February 2023. That weakens confidence in ongoing registry maintenance.
All recent commits come from one contributor, leaving the project dependent on a single maintainer. The repository owner is an individual, so there is no organizational backing shown to compensate for that concentration.
The repository recorded one commit in the last three months from one active maintainer. This shows some activity, but the pace is too thin to demonstrate strong ongoing maintenance.
The repository has no security policy. For a database-backed component, this is a transparency gap that makes vulnerability reporting and maintenance expectations less clear.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
hyperf/di Version ^3.0 | — | — |
hyperf/cache Version ^3.0 | — | — |
hyperf/event Version ^3.0 | — | — |
hyperf/database Version ^3.0 | — | — |
hyperf/http-server Version ^3.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.