Package Health

ecomdev/reactive-socket

Usable with caveats: it has a clear MIT license, matching repository, tests, changelog, and a stable release, but development appears to have stopped in October 2018. Install-time scripts and the absence of security tooling or a security policy add maintenance risk.

Latest 1.1.1PackagistPackagist

57%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

75

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

78

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

67

Health Score Breakdown

Lifecycle scriptscaution

The package defines post-install and post-update scripts, which increase installation complexity and supply-chain exposure compared with a package without lifecycle hooks.

Release historycaution

The package has had no release in nearly eight years and none in the last 12 months, indicating that it is no longer actively maintained despite four historical releases.

Repo commit activitycaution

There were no commits or active maintainers in the last three months, and the repository's last push was in 2018, leaving current maintenance capacity un demonstrated.

Repo popularitycaution

The repository has one star, no forks, and no watchers. This is weak supporting evidence, but low popularity alone does not make a small, otherwise coherent package unsafe to use.

Repo toolingcaution

Composer build tooling is present, but no security-scanning tools are configured, leaving a transparency and maintenance gap.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

Ivan Chepurnyi

Direct Dependencies

No direct dependencies.

Weekly Downloads

Info

Last Published
7 years ago
Created
8 years ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform