Real-time engine for building reactive web applications in PHP
78%
Total Score
healthy
Active development supports adoption, but all workflow actions are unpinned and 98% of recent commits come from one contributor.
The package and repository are owned by the same individual user account rather than an organization, so the concentrated contributor activity represents a genuine single-maintainer dependency.
Recent activity is highly concentrated: one contributor made 328 of 334 commits, or about 98%, leaving the project dependent on a single primary contributor.
Composer build tooling is present, but no security scanning tools were detected. The missing scanning is a hygiene gap rather than evidence of abandonment.
The repository has no security policy, leaving vulnerability reporting and response expectations unclear for a framework that may handle application traffic.
Version v0.14.2 is not a prerelease, but the package remains below 1.0, so its API may still change more than that of a mature major release.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
nyholm/psr7 Version ^1.8 | — | — |
openswoole/core Version ^26.2 | — | — |
psr/http-server-middleware Version ^1.0 | — | — |
starfederation/datastar-php Version ^1.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.