It has a clear MIT license, repository tests, release notes, and organization backing. The stable major version and focused package reduce adoption friction, but maintenance visibility is limited.
63%
Total Score
67
88
100
The package has seven releases since December 2017, but none in the last three years; the long median interval and stale latest release reduce confidence in ongoing maintenance.
The repository recorded zero commits and zero active maintainers over the last three months, indicating little current maintenance capacity.
There were no new or closed issues or pull requests in the last month, with four issues still open; this is consistent with the broader signs of limited recent activity.
Composer build tooling is present, but no security scanning tools were detected; this is a modest transparency gap rather than evidence of unsafe code.
The sole workflow was fully analyzed with no high-confidence findings or untrusted execution sinks, but all four action references are unpinned, leaving avoidable build-integrity risk.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
amphp/amp Version ^3 | — | — |
amphp/sync Version ^2.1 | — | — |
amphp/parallel Version ^2.2.3 | — | — |
amphp/serialization Version ^1 | — | — |
laravel/serializable-closure Version ^1.3 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.