The repository has active recent work, tests, a changelog, security scanning, and a security policy. GitHub Actions use read-only permissions but all four action references are unpinned, and install-time scripts add a small supply-chain maintenance concern.
82%
Total Score
67
100
100
75
The package runs post-install and post-update Composer scripts, which add execution and maintenance surface during dependency operations even though no concrete harmful behavior is shown here.
The registry namespace and repository are owned by the same individual account, so there is no organization-level handoff capacity shown; active commits and a second contributor provide some compensation.
Two contributors are active, but the top contributor accounts for about 69% of recent commits, leaving some concentration risk; the second contributor's 31% share partly compensates.
The single workflow was fully analyzed, uses read-only permissions, and has no untrusted checkout, injection, or audit findings; however, all four action references are unpinned, weakening build reproducibility and update safety.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
amphp/amp Version ^3.1.3 | — | — |
danog/php-rtc-ice Version ^1.1.18 || ^2.0 | — | — |
danog/php-rtc-rtp Version ^1.1.13 || ^2.0 | — | — |
danog/php-rtc-sdp Version ^1.1.6 | — | — |
danog/php-rtc-sctp Version ^1.1.5 || ^2.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.