The source is small and has no security policy; both workflow actions are unpinned. Recent activity and release notes provide useful maintenance evidence, but one-person ownership limits continuity.
42%
Total Score
50
100
75
75
Packagist marks the entire package as abandoned, with no replacement named. This is a substantial adoption and continuity risk despite other signs of recent work.
The registry and repository are owned by the same individual account, confirming a matching source rather than a misleading namespace. It does not provide organizational maintenance redundancy.
The package has 13 releases over about six years and one release in the last 12 months, indicating a mature but relatively slow cadence. The latest release is recent, which partly offsets the slower pace.
All recent commits came from one contributor, so maintenance depends on a single active person. The repository is user-owned rather than organization-backed, providing no shown handoff capacity.
The repository had two commits in the last three months and one active maintainer. This is evidence of ongoing work, but the volume is limited.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
react/socket Version ^1.6 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.