The linked project has tests, release notes for this version, a declared MIT license, and security tooling. Recent commit activity is absent, so ongoing maintenance is uncertain despite the repository being backed by an organization.
20%
Total Score
50
79
100
Packagist marks the entire package as abandoned and explicitly recommends amphp/byte-stream, making this release unsuitable as a new dependency despite other healthy evidence.
The package has 51 releases since 2017, but none in the last 12 months; this supports the abandonment concern rather than offsetting it.
The linked repository recorded zero commits and zero active maintainers in the last three months, leaving current maintenance capacity unproven.
The sole workflow was fully analyzed with no audit findings or untrusted execution sinks; all four action references are unpinned, a minor reproducibility and supply-chain hygiene gap.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
amphp/amp Version ^3 | — | — |
amphp/sync Version ^2 | — | — |
amphp/parser Version ^1.1 | — | — |
amphp/pipeline Version ^1 | — | — |
revolt/event-loop Version ^1 || ^0.2.3 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.