The source is small but has tests, a clear MIT license, and no install-time scripts. There has been no release or commit activity since April 2019, with no active maintainers in the last three months, so ongoing compatibility is uncertain.
38%
Total Score
0
67
50
The package has only two releases, and none in the last 12 months; the latest release was in April 2019. This long period without published maintenance materially raises abandonment risk.
The repository recorded zero commits and zero active maintainers in the last three months, consistent with the release gap and providing no evidence of current maintenance capacity.
The repository has zero stars, one fork, and one watcher. Popularity is only supporting evidence, but these very low adoption indicators provide little evidence of a broad support community.
Composer is used for builds, which fits the package ecosystem, but no security scanning tools were detected. This is a hygiene gap that adds some transparency risk alongside the broader maintenance concerns.
The repository has no security policy, leaving vulnerability-reporting expectations unclear. This is a transparency gap, though it is less significant than the package's prolonged inactivity.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
carno-php/http Version ^1.0 | — | — |
carno-php/socket Version ^1.0 | — | — |
carno-php/cluster Version ^1.0 | — | — |
carno-php/promise Version ^1.0 | — | — |
carno-php/coroutine Version ^1.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.