The package has a clear README, MIT licensing, repository tests, and release notes for this version. However, it has no security policy or scanning, and maintenance evidence is limited to its initial release with no commits in the past three months.
58%
Total Score
50
83
50
The package runs post-install and post-update Composer scripts, adding execution during dependency operations. This is a manageable transparency and review concern rather than a severe health risk.
The repository is owned by an individual user rather than an organization. That is valid for an open-source project, but it provides less visible backing against maintainer loss than organizational ownership.
This is a young package, about three months old, with only one release and no established release cadence. That limits evidence of sustained maintenance, though its short history is not abandonment by itself.
There were zero commits and zero active maintainers in the past three months. For a package only about three months old, this leaves maintenance capacity uncertain and raises abandonment risk.
The repository has zero stars, forks, and watchers. Popularity is only supporting evidence, but the absence of any visible community adoption provides no compensating maturity signal.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
hyperf/di Version ^3.1 | — | — |
hyperf/cache Version ^3.1 | — | — |
96qbhy/simple-jwt Version ^v1.5 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.