The MIT license, substantial README, matching repository, and repository tests improve transparency. Unpinned workflow actions and an archived action add maintenance risk, while no security policy leaves oversight unclear.
42%
Total Score
0
100
79
75
The package has had only 5 releases, all ending in July 2022, with no releases in the last 12 months despite being over four years old. This is strong evidence of abandonment risk.
The repository recorded 0 commits and 0 active maintainers in the last 3 months, consistent with the release history and indicating no current maintenance capacity.
The repository has 1 star, 0 forks, and 0 watchers. Popularity is only supporting evidence, but these figures provide little indication of a broad support base.
The repository has no security policy, leaving vulnerability reporting and disclosure expectations undocumented. This is a transparency gap, though it does not by itself show unsafe code.
Both workflows were analyzed without untrusted triggers or script injection, but all 4 action references are unpinned and one high-confidence medium-severity finding uses an archived action. These weaken build reproducibility and maintenance hygiene.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
hyperf/guzzle Version ^2.2|^3.0 | — | — |
hyperf/context Version ^2.2|^3.0 | — | — |
psr/http-server-middleware Version ^1.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.