The project has clear documentation, tests in its repository, security reporting, and organization backing. Its release cadence is currently inactive, while the repository remains maintained and the latest release includes focused fix notes. All three workflow actions are unpinned, adding a modest reproducibility concern.
72%
Total Score
75
94
100
The package is mature, with releases since 2017, but it has made no registry release in the last 12 months and its latest release was nearly two years ago. That weakens confidence in ongoing consumer-facing maintenance.
There were no commits and no active maintainers in the last three months. This is a meaningful maintenance slowdown, although the repository's recent push and established organization backing provide some compensation.
The only workflow was fully analyzed with no dangerous triggers, untrusted checkouts, or audit findings. However, all 3 action references are unpinned, leaving a modest supply-chain reproducibility gap.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
amphp/amp Version ^3 | — | — |
amphp/parser Version ^1 | — | — |
amphp/socket Version ^2 | — | — |
amphp/pipeline Version ^1 | — | — |
amphp/byte-stream Version ^2 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.