The package has MIT licensing, useful documentation, and repository tests. Its workflow leaves all six actions unpinned, while the repository has no security scanning or policy.
55%
Total Score
75
79
75
The package has 67 releases, but none in the last 12 months; its latest registry release was about three years ago. This materially raises maintenance and abandonment concerns.
The repository recorded zero commits and zero active maintainers in the last three months. Despite the recent push timestamp, this shows no observed ongoing development in the measured period.
Composer build tooling is present, but no security scanning tools were detected. For a server package, that is a meaningful security-maintenance gap.
The repository has no security policy. The README provides a security contact, which partly helps disclosure transparency, but it does not replace a documented policy.
The assessed version is a beta, while the registry reports 1.14.1 as the latest stable major version. That makes this release less suitable as a default dependency than a stable release.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
react/promise Version ^2.8 | — | — |
cboden/ratchet Version ^0.4.1 | — | — |
guzzlehttp/psr7 Version ^1.7|^2.0 | — | — |
illuminate/http Version ^6.3|^7.0|^8.0|^9.0 | — | — |
clue/redis-react Version ^2.5 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.