The project has had no commits in three months and only one release, so its maintenance track record is still unproven. A complete README, repository tests, MIT licensing, and no install-time scripts provide useful safeguards, but the two unpinned workflow actions and missing security policy leave notable hygiene gaps.
58%
Total Score
50
100
75
67
The repository is owned by an individual account rather than an organization, so the project does not show organizational backing to compensate for its limited history.
This release is from a package only 132 days old with one release total, so there is not enough history to establish a dependable maintenance pattern.
There were zero commits and zero active maintainers during the last three months, a meaningful warning for a package whose only release is also its initial release.
There has been no issue or pull-request activity in the last month; with no broader history, this provides little evidence of an active support cycle.
The repository has zero stars, forks, and watchers, so there is no community adoption signal to offset the short maintenance history, though popularity alone is not decisive.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
amphp/amp Version ^3.0 | — | — |
amphp/socket Version ^2.0 | — | — |
amphp/byte-stream Version ^2.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.