Its MIT declaration and clean package contents provide some transparency, and installation has no lifecycle scripts. The source repository has no recent commit activity, tests, changelog, or security policy, leaving maintenance and project oversight uncertain.
58%
Total Score
50
50
79
83
Five runtime dependencies create a meaningful dependency surface for this small library, though the signal provides no evidence that any dependency is unsafe or poorly maintained.
The artifact has no README, which is a minor consumer-facing gap for a library; absent tests and changelog files are normal for published artifacts, and the repository also provides none.
The package is 212 days old but has only one release, so there is little release history from which to judge sustained maintenance.
The repository recorded zero commits and zero active maintainers during the last three months, a concrete sign that maintenance may have stalled.
The project uses Composer for builds, but no security scanning tooling was detected, leaving a modest repository-hygiene gap.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
appkit/async Version ^1.0 | — | — |
appkit/health Version ^1.0 | — | — |
react/promise Version ^3.3 | — | — |
appkit/start-stop Version ^1.0 | — | — |
evenement/evenement Version ^3.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.