It includes a README, tests, release notes, and an MIT license. Organization backing and a post-install script provide some context, but the narrow release history and aging codebase limit confidence in continued support.
42%
Total Score
50
75
50
Only two releases exist, with none in the last 12 months; the latest registry release was about 4 years ago and release intervals are very long. This is strong evidence of limited ongoing maintenance.
The repository recorded no commits and no active maintainers in the last 3 months, while its last push was about 9 years ago. The release history does not compensate for this long period of source inactivity.
A post-install Composer lifecycle script runs during installation. This adds operational and supply-chain exposure that developers should understand, although the signal alone is not evidence that the package is unsafe.
The linked repository has no security policy. For a backend service handling authentication, data, and credentials, this weakens vulnerability-reporting transparency.
v0.4.0 is not marked as a prerelease, so the assessed release is presented as a normal stable release. Its pre-1.0 major version still indicates a less mature compatibility commitment.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
endel/slim Version dev-master | — | — |
react/socket Version 0.4.* | — | — |
doctrine/dbal Version 2.* | — | — |
cboden/ratchet Version 0.3.* | — | — |
patchwork/utf8 Version ~1.2 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.