The project has a long release history, a current stable release, clear documentation, tests, and release notes. Its single recent maintainer and three unpinned workflow actions are minor weaknesses, while the repository remains active and unarchived.
82%
Total Score
88
100
94
83
Only one registry account has publish access, which creates some continuity risk, although the repository and release history show an established project rather than an abandoned package.
Composer build tooling is present, but no security scanning tools were detected. This is a minor transparency and maintenance gap rather than evidence that the release is unsafe.
The repository has no security policy, leaving vulnerability-reporting expectations undocumented for consumers and maintainers.
The sole workflow was fully analyzed with no dangerous triggers, untrusted checkouts, or audit findings. However, all three action references are unpinned, which weakens build reproducibility.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
react/socket Version ^1.17 | — | — |
react/promise Version ^3.3 || ^2.1 || ^1.2.1 | — | — |
react/event-loop Version ^1.6 | — | — |
react/promise-timer Version ^1.11 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.