The package has a clear MIT license, a substantial README, repository tests, and no install-time scripts. Its small maintainer base, absent security policy, and lack of security scanning add risk for a package with no recorded development activity.
38%
Total Score
25
71
75
Only two releases exist, both from January 2023, with no releases in the last 12 months; this indicates the package is effectively unmaintained.
The repository recorded zero commits and zero active maintainers over the last three months, consistent with the long release gap and raising abandonment risk.
One registry maintainer is a thin publishing base for a library, although the linked repository does identify the same individual owner.
The repository has zero stars and forks and only one watcher. Popularity is supporting evidence rather than a verdict, but these numbers provide little evidence of a broader maintenance community.
Composer build tooling is present, but no security scanning tools were detected, reducing ongoing vulnerability-detection coverage.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
react/http Version ^1.1 | — | — |
amphp/artax Version ^3 | — | — |
react/promise Version ^2.7 | — | — |
clue/block-react Version ^1.3 | — | — |
unreal4u/dummy-logger Version ^1.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.