The small codebase has a README, tests, an MIT license, and an active repository link. Its single publisher and lack of commits or releases since March 2024 make future fixes uncertain.
58%
Total Score
50
81
75
Only one registry account can publish releases. The repository is organization-owned, which provides some backing, but there is no observed activity here showing that the organization offsets the narrow publishing base.
The package has 9 releases since February 2019, but none in the last 12 months and the latest was released in March 2024. This indicates a long maintenance gap for a still-unmaintained-looking pre-1.0 package.
The repository recorded 0 commits and 0 active maintainers in the last 3 months, consistent with the release gap and reducing confidence that issues will receive fixes.
Composer is used for build and dependency management, but no security scanning tool is detected. This is a hygiene gap, not evidence that the package is unsafe.
The repository has no security policy, leaving vulnerability-reporting expectations undocumented. This modestly reduces transparency but does not outweigh the clearer maintenance concern.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
react/stream Version >=1.1 | — | — |
react/promise Version ^2|^3 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.