Documentation, licensing, and a security policy make integration and ownership expectations clear. Pin CI actions before relying on its build process, and monitor continuity because maintenance is concentrated in one person.
73%
Total Score
67
100
86
83
The repository is owned by an individual account, so the single-contributor concentration is not backed by an organization that could readily transfer maintenance.
All 62 recent commits came from one contributor, creating a meaningful continuity and handoff risk despite the high commit volume. The repository is user-owned rather than organization-owned, so no organizational backing compensates for this concentration.
Composer build tooling is present, but no repository security-scanning tools were detected. The missing scanning is a hygiene gap rather than evidence of abandonment, especially since other repository transparency signals are present.
Version v0.9.0 is not a stable major release, so its API may still change. It is not marked as a prerelease, and recent releases have no prerelease share, which partly offsets the maturity concern.
The single workflow was fully analyzed with no trigger-to-untrusted-code findings or auditor findings. However, all three action references are unpinned, leaving the CI build exposed to mutable action changes; the absence of a top-level permissions block is acceptable here and is not a risk by itself.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
psr/log Version ^3.0 | — | — |
amphp/amp Version ^3.0 | — | — |
innis/nostr-core Version ^0.8 | — | — |
amphp/http-server Version ^3.0 | — | — |
amphp/websocket-server Version ^4.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.