Package Health

amphp/websocket

The project has clear documentation, tests in its repository, security reporting, and organization backing. Its release cadence is currently inactive, while the repository remains maintained and the latest release includes focused fix notes. All three workflow actions are unpinned, adding a modest reproducibility concern.

Latest v2.0.4PackagistPackagist

72%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

75

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

94

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

100

Health Score Breakdown

Release historycaution

The package is mature, with releases since 2017, but it has made no registry release in the last 12 months and its latest release was nearly two years ago. That weakens confidence in ongoing consumer-facing maintenance.

Repo commit activitycaution

There were no commits and no active maintainers in the last three months. This is a meaningful maintenance slowdown, although the repository's recent push and established organization backing provide some compensation.

Workflow auditcaution

The only workflow was fully analyzed with no dangerous triggers, untrusted checkouts, or audit findings. However, all 3 action references are unpinned, leaving a modest supply-chain reproducibility gap.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

Aaron Piotrowski
Niklas Keller
Bob Weinand

Direct Dependencies

DependencyLast ReleaseScore
amphp/amp
Version ^3
amphp/parser
Version ^1
amphp/socket
Version ^2
amphp/pipeline
Version ^1
amphp/byte-stream
Version ^2

Weekly Downloads

Info

Last Published
1 year ago
Created
9 years ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform