The repository includes tests, release notes, a security policy, and automated scanning. Recent work involves three contributors, though most commits come from one person; install and update scripts deserve review.
84%
Total Score
83
50
100
75
The package declares 41 runtime dependencies, reflecting a broad and operationally complex dependency surface. This is not inherently unhealthy, but it increases maintenance exposure compared with a small dependency set.
Post-install and post-update scripts run during dependency operations, creating an additional execution surface that deserves review even though this signal alone does not show harmful behavior.
Three contributors were active recently, but the top contributor made 75% of commits, leaving maintenance substantially concentrated in one person.
The single analyzed workflow has read-only permissions and no detected injection or high-severity findings, but all 3 action references are unpinned, reducing build reproducibility and integrity.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
psr/log Version ^3.0.2 | — | — |
amphp/amp Version ^3.1.1 | — | — |
amphp/dns Version ^2.4.0 | — | — |
amphp/log Version ^2 | — | — |
danog/ipc Version ^1.0.1 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.