The README, MIT license, and matching source repository make it understandable to integrate. Its single maintainer and absent security policy leave little evidence of ongoing support.
42%
Total Score
50
86
75
The package has 9 releases, but its latest release was in September 2019 and it has had no releases in the last 12 months. That long gap is a meaningful abandonment concern.
The repository recorded 0 commits and 0 active maintainers in the last 3 months, consistent with the package's prolonged lack of releases. No provided maintenance signal compensates for this inactivity.
The repository has 0 stars, 0 forks, and 0 watchers. Popularity is only supporting evidence, but these values provide no community signal to offset the maintenance concerns.
The repository has no security policy and no security scanning tools. This does not make the package unsafe by itself, but it reduces transparency for a client handling authentication and network connections.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
psr/log Version ~1.0 | — | — |
react/socket Version ~0.8 | — | — |
react/promise Version ~2.0 | — | — |
binsoul/net-mqtt Version ~0.2 | — | — |
react/event-loop Version ^0.4.3 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.