Risky to depend on: this package has had only one release, with no new releases or repository commits for about six years. Its linked repository does not match the package name, making ownership and ongoing maintenance unclear.
32%
Total Score
33
56
80
The package has only one release, published about six years ago, with no releases in the last 12 months. That strongly limits evidence of ongoing maintenance.
The repository had zero commits and zero active maintainers in the last three months, with its last push about six years ago. This is strong evidence of abandonment risk.
The linked repository name does not match the package name, and no README mention was collected. The repository may not actually belong to this package, which weakens provenance and maintenance confidence.
The package contains only RunSocket.php and composer.json, and the repository has the same two files. This is transparent and compact, but provides little evidence of project maturity or supporting documentation.
The artifact has no README, tests, or changelog; the missing tests and changelog are normal for a tiny published artifact, but the missing README reduces usability for consumers. The exact release has a GitHub release, which provides some release documentation evidence.
We didn't find any vulnerabilities for this package.
No maintainer information available.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.