Clear licensing, repository tests, security scanning, and a security policy add useful protection. The install hooks and unpinned workflow actions merit review, while the active second contributor reduces concentration risk.
78%
Total Score
67
94
67
The package runs post-install and post-update Composer scripts, which increase installation-time trust requirements even though this signal does not establish harmful behavior.
The registry namespace and repository owner match, and the repository is owned by a user rather than an organization; this provides identity consistency but less organizational handoff capacity.
The package is only 58 days old but has 44 releases, with releases arriving roughly every 80 minutes at the median; this shows active work but also an unusually fast cadence for a dependency.
Two contributors are active, and the second contributor made 29 commits, partly offsetting the leading contributor's 69% share; the small contributor base still leaves some continuity risk.
The only workflow was fully analyzed, uses read-only permissions, and has no untrusted checkouts or script injection findings. However, all 3 action references are unpinned, leaving avoidable action-supply-chain exposure.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
amphp/amp Version ^3.1.3 | — | — |
ramsey/uuid Version ^4.9.3 | — | — |
amphp/pipeline Version ^1.2.7 | — | — |
danog/php-rtc-ntp Version ^1.1.6 | — | — |
danog/php-rtc-sdp Version ^1.1.6 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.