Regular releases over the past year and a stable version are reassuring. MIT licensing, an active organization-owned repository, and a matching package tree provide useful transparency, though project checks remain limited.
68%
Total Score
67
100
86
75
The package includes a README and release notes for this exact version, but the README is only 8 characters long and neither the artifact nor repository contains tests or a changelog. Missing tests and changelog are normal for published artifacts, while the extremely minimal README weakens consumer transparency.
All three recent commits came from one contributor, leaving maintenance dependent on a single active contributor. Organization ownership provides some handoff capacity but does not remove the concentration risk.
Three commits in the past three months show some ongoing maintenance, though activity is modest for a package intended to be depended on.
Composer is used for builds, but no security-scanning tools were detected, leaving automated security checks unobserved.
The repository has no security policy. This is a transparency and incident-response gap, although it is not evidence that the release is unsafe.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
hyperf/di Version ~3.2 | — | — |
hyperf/logger Version ~3.2 | — | — |
hyperf/collection Version ~3.2 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.