The MIT license, tests, README, and release notes make the package easy to inspect and integrate. Its small maintenance footprint and unpinned CI actions leave more upkeep and build-integrity risk than a mature dependency.
52%
Total Score
50
80
50
The package has had only two releases, both in March 2024, with no release in more than two years. That long gap lowers confidence in ongoing maintenance for a 0.x library.
The repository recorded no commits and no active maintainers in the last three months, consistent with the broader absence of releases and indicating limited current maintenance.
The repository has no published security policy, leaving vulnerability reporting and response expectations unclear for a package that handles network connections.
The latest version is v0.1.1 and is not a stable major release, so compatibility expectations are weaker even though it is not marked as a prerelease.
The single workflow was fully analyzed with no dangerous triggers, untrusted checkouts, or audit findings, but all three action references are unpinned, reducing build reproducibility and supply-chain hygiene.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
amphp/amp Version ^3.0 | — | — |
revolt/event-loop Version ^1.0 | — | — |
amphp/websocket-client Version ^2.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.