The package has tests, a changelog, a clear MIT license, and organization backing. Its workflow audit found no dangerous patterns, though two actions are unpinned and no security policy is published.
68%
Total Score
88
100
81
67
The package has 18 releases over roughly seven years, but none in the past 12 months; the latest release was about 1 year and 19 days ago. This suggests slowing maintenance despite a historically established release pattern.
There were no commits and no active maintainers in the past three months. Together with the lack of releases in the past year, this is meaningful evidence of currently stalled maintenance.
The repository has zero stars and forks and only one watcher. Low popularity is supporting evidence rather than a verdict, but it means limited external adoption and review are available to compensate for stalled activity.
Composer is used as the build tool, but no security scanning tools were detected. The missing scanner is a hygiene gap rather than evidence of a dependency problem.
The repository has no published security policy. This reduces transparency around vulnerability reporting, though the package still has a license, tests, and a maintained project structure.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
psr/log Version >=1.1 | — | — |
gipfl/json Version >=0.1 | — | — |
react/stream Version >=1.0 | — | — |
gipfl/openrpc Version ^0.2.1 | — | — |
react/promise Version >=2.7 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.