MIT licensing, repository tests, and an organization-backed project provide useful baseline confidence. The very short README and six unpinned workflow actions leave documentation and build-integrity gaps.
58%
Total Score
50
78
75
There were no commits and no active maintainers in the last three months, consistent with a project whose last push was about two years ago and raising abandonment risk.
Tests are present in the package and repository, but the 14-character README provides almost no consumer guidance; the absent changelog is normal packaging practice.
The package has only three releases, all clustered in July 2024, with no releases in the last 12 months; this is a meaningful maintenance concern.
The repository has zero stars and forks and only one watcher, indicating little public adoption; this is supporting caution rather than a verdict by itself.
Composer build tooling is present, but no security-scanning tooling was detected, leaving a modest repository hygiene gap.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
psr/log Version ^1.0|^3.0 | — | — |
amphp/process Version ^2.0 | — | — |
amphp/byte-stream Version ^2.1 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.