Package Health

bugover/laravel-websocket

The repository is active enough to remain available, with tests, a changelog, and a matching MIT license. Its workflow leaves all five actions unpinned, and the project has no security policy or security scanning.

Latest 2.1.0PackagistPackagist

58%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

50

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

88

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

50

Health Score Breakdown

Project backingcaution

The repository is owned by a user account rather than an organization, indicating limited visible institutional backing. This is supporting context, not a verdict by itself.

Release historycaution

The package has 26 releases, but none in the last 12 months; its latest release was over a year ago. This is meaningful evidence of slowed maintenance despite a substantial release history.

Repo commit activitycaution

The repository recorded zero commits and zero active maintainers in the last three months, reinforcing the release-history evidence that maintenance has stalled.

Repo toolingcaution

Composer is used for the build, but no security scanning tools are configured. This leaves a maintenance and transparency gap for a package handling WebSocket server functionality.

Security policycaution

The repository has no security policy, so there is no documented process for reporting or handling vulnerabilities.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

naykunaMkatr
Freek Van der Herten

Direct Dependencies

DependencyLast ReleaseScore
react/dns
Version ^1.0.0
—
—
react/http
Version ^1.9.0
—
—
react/promise
Version ^2.8.0|^3.0.0
—
—
bugover/ratchet
Version ^1.1.0
—
—
illuminate/http
Version ^11.0.0|^12.0.0
—
—

Weekly Downloads

Info

Last Published
1 year ago
Created
2 years ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform