The package includes a substantial README, changelog, release notes, tests, and a matching MIT license. Its CI has no dangerous findings, but all three action references are unpinned and the repository has no security policy.
68%
Total Score
75
88
50
The latest registry release was in September 2022, with no releases in the last 12 months and only six releases overall. This is a meaningful maintenance concern, although the linked repository was pushed more recently.
There were no commits or active maintainers in the measured three-month window. The recent repository push prevents this from indicating clear abandonment, but the lack of sustained activity remains a caution.
The project uses Composer, but no security scanning tool was detected. This is a modest transparency and maintenance gap rather than evidence that the package is unsafe.
The repository has no published security policy, leaving vulnerability reporting and response expectations unclear for a package that handles SSH connections.
The sole workflow was fully analyzed and had no dangerous audit findings or untrusted triggers. However, all three action references are unpinned, which weakens build reproducibility and supply-chain hygiene.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
react/socket Version ^1.12.0 | — | — |
react/stream Version ^1.2 | — | — |
react/promise Version ^3 || ^2.1 || ^1.2.1 | — | — |
clue/socks-react Version ^1.4 | — | — |
react/event-loop Version ^1.2 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.