Risky to adopt: the package has had no release or repository activity for over six years, with no tests or README to support maintenance or integration. It is not deprecated or archived and has a declared MIT license, but the project appears effectively abandoned.
35%
Total Score
0
63
75
The latest release was published over six years ago, and there have been no releases in the last 12 months. The five releases were initially frequent, but the prolonged gap is strong evidence of abandonment risk.
The repository has had zero commits and zero active maintainers in the last three months, consistent with the release history showing no activity for over six years. This materially reduces confidence that defects or compatibility issues will be addressed.
The package includes release notes for this version, which provides some documentation of the change, but it has no README or tests in the published artifact or repository. The missing README is a real integration gap for a small library, while missing tests increases maintenance risk.
The repository has zero stars and zero forks, with one watcher. Popularity is not required for health, but these very limited signs of adoption provide no supporting evidence against the strong inactivity concerns.
Composer is used for the build, but no security scanning tools are configured. This is a transparency and maintenance gap, although the absence of workflows means it does not create an active workflow risk.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
react/socket Version ^1.4 | — | — |
brunonatali/tools Version >=0.5 | — | — |
binsoul/net-mqtt-client-react Version 0.7.2 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.