The license, README, and active repository provide useful transparency. CI uses four unpinned actions and the project has no security policy, so operational safeguards are limited.
65%
Total Score
88
83
75
The package is newly published, with 13 releases all appearing within the same day. That shows active initial work but provides no longer-term maintenance history.
All 24 recent commits came from one contributor, leaving maintenance dependent on a single active developer. Organization backing provides some handoff capacity but does not remove the concentration concern.
The repository has only 1 star and no forks or watchers. This is limited supporting evidence, but popularity alone does not outweigh the active commit history and organization backing.
Composer build tooling is present, but no security scanning tools were detected. The missing scanning coverage is a modest transparency and maintenance gap.
The repository has no security policy, leaving vulnerability reporting and response expectations undocumented.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
psr/log Version ^3.0 | — | — |
react/dns Version ^1.13 | — | — |
ramsey/uuid Version ^4.7 | — | — |
react/async Version ^4.3 | — | — |
react/socket Version ^1.16 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.