The single-user project lacks tests, a security policy, and security scanning. A short README, exact-version release notes, and a non-archived repository provide some transparency, but not enough to offset the maintenance concerns.
44%
Total Score
25
67
50
The package has 12 releases, but none in the last two years; the latest release was in September 2024. This is strong evidence of stalled maintenance for a package with multiple integrations.
The repository recorded no commits and no active maintainers in the past three months, consistent with the long release gap. The repository is not archived, but there is no recent activity showing ongoing care.
The manifest declares “deving,” but no license was detected and no license file is present in either the package or repository. That leaves reuse and redistribution rights unclear.
Only one registry account has publish access, and the repository is owned by an individual rather than an organization. That creates a thin publishing and continuity base, with no other provided evidence of active contributors.
Composer is used for the build, but no security-scanning tools are configured. The missing scanning is a modest hygiene concern rather than evidence of unsafe code by itself.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
hyperf/redis Version ~3.1.0 | — | — |
hyperf/guzzle Version ^3.1 | — | — |
hyperf/framework Version ~3.1.0 | — | — |
wechatpay/wechatpay Version ^1.4 | — | — |
yurunsoft/phpmailer-swoole Version ^1.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.