The package is clearly documented and has received frequent releases over the past four months. All recent repository work comes from one contributor, and the project has no security policy or scanning tools, leaving limited maintenance and security depth.
67%
Total Score
50
100
83
75
The repository is owned by an individual user rather than an organization, so the one-person maintainer and bus-factor concerns are not compensated by visible organizational backing.
One contributor made all seven recent commits, creating a significant single-person continuity risk; the repository is user-owned, so no organizational backing offsets that concentration.
Seven commits in the last three months show ongoing work, though the activity is limited in volume and concentrated in one maintainer.
The repository has zero stars, forks, and watchers. This is weak supporting evidence, but it does not by itself outweigh the recent release and commit activity.
Composer build tooling is present, but no security scanning tools were detected, leaving a modest gap in ongoing project hygiene.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
guzzlehttp/guzzle Version ^7.0 | — | — |
textalk/websocket Version ^1.6 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.