Usable with caveats: the package is backed by an active organization, has a clear license, tests in the repository, and a recent release. Maintenance is thin, with only one recent commit from one contributor, limited release activity, and no security policy or workflow permission declaration.
68%
Total Score
63
50
81
80
The package relies on 11 runtime dependencies, including several messaging and asynchronous networking components; this is a relatively broad dependency surface that increases maintenance and compatibility exposure.
The package has been maintained since 2018 with 16 releases, but only one release appeared in the last 12 months and releases are separated by about 155 days, indicating a slow cadence.
All recent commits came from one contributor, creating a meaningful continuity risk; organization backing helps with handoff potential but no second active contributor is shown.
Only one commit was made in the last three months by one active maintainer, indicating limited recent development despite the recent repository push.
There are no open issues or pull requests, which is orderly but provides little evidence of an active community or ongoing issue resolution.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
react/dns Version ^1.4 | — | — |
enqueue/dsn Version ^0.10.8 | — | — |
ratchet/pawl Version ^0.4.3 | — | — |
react/promise Version ^2.8 | — | — |
thruway/client Version ^0.5.5 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.