Package Health

yevheniizhabchyk/hyperf-auth

The package has a clear README, MIT licensing, repository tests, and release notes for this version. However, it has no security policy or scanning, and maintenance evidence is limited to its initial release with no commits in the past three months.

Latest v3.2.0PackagistPackagist

58%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

50

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

83

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

50

Health Score Breakdown

Lifecycle scriptscaution

The package runs post-install and post-update Composer scripts, adding execution during dependency operations. This is a manageable transparency and review concern rather than a severe health risk.

Project backingcaution

The repository is owned by an individual user rather than an organization. That is valid for an open-source project, but it provides less visible backing against maintainer loss than organizational ownership.

Release historycaution

This is a young package, about three months old, with only one release and no established release cadence. That limits evidence of sustained maintenance, though its short history is not abandonment by itself.

Repo commit activitycaution

There were zero commits and zero active maintainers in the past three months. For a package only about three months old, this leaves maintenance capacity uncertain and raises abandonment risk.

Repo popularitycaution

The repository has zero stars, forks, and watchers. Popularity is only supporting evidence, but the absence of any visible community adoption provides no compensating maturity signal.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

No maintainer information available.

Direct Dependencies

DependencyLast ReleaseScore
hyperf/di
Version ^3.1
hyperf/cache
Version ^3.1
96qbhy/simple-jwt
Version ^v1.5

Weekly Downloads

Info

Last Published
3 months ago
Created
3 months ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform