The repository is active enough to remain available, with tests, a changelog, and a matching MIT license. Its workflow leaves all five actions unpinned, and the project has no security policy or security scanning.
58%
Total Score
50
88
50
The repository is owned by a user account rather than an organization, indicating limited visible institutional backing. This is supporting context, not a verdict by itself.
The package has 26 releases, but none in the last 12 months; its latest release was over a year ago. This is meaningful evidence of slowed maintenance despite a substantial release history.
The repository recorded zero commits and zero active maintainers in the last three months, reinforcing the release-history evidence that maintenance has stalled.
Composer is used for the build, but no security scanning tools are configured. This leaves a maintenance and transparency gap for a package handling WebSocket server functionality.
The repository has no security policy, so there is no documented process for reporting or handling vulnerabilities.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
react/dns Version ^1.0.0 | — | — |
react/http Version ^1.9.0 | — | — |
react/promise Version ^2.8.0|^3.0.0 | — | — |
bugover/ratchet Version ^1.1.0 | — | — |
illuminate/http Version ^11.0.0|^12.0.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.