The MIT license and small runtime dependency set make adoption easier to assess. Maintenance and project hygiene are weak, with no activity since July 2021, no tests or README, no security policy, and an incomplete workflow pinning setup.
38%
Total Score
0
100
67
50
The package has had no release in over five years: its latest release was July 2021, with four releases total and none in the last 12 months. This is strong evidence of abandonment risk, although the repository is not archived.
The repository recorded zero commits and zero active maintainers in the last three months, consistent with the long release gap and indicating no current maintenance capacity.
The artifact has no README, tests, or changelog. Missing tests and changelog are normal for published artifacts, but a missing README reduces transparency for a library consumers must integrate with.
Composer is used for builds, which is appropriate, but the repository reports no security scanning tools. This is a hygiene gap that adds modest maintenance risk rather than making the release unfit on its own.
The repository has no security policy, leaving no documented process for reporting or handling vulnerabilities. This weakens transparency for a package used in service infrastructure.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
hyperf/nacos Version ~2.2.0 | — | — |
hyperf/utils Version ~2.2.0 | — | — |
hyperf/contract Version ~2.2.0 | — | — |
hyperf/service-governance Version ~2.2.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.