The package is documented, licensed, tested in its repository, and has no install-time scripts. Its single release and lack of recent commits weaken confidence in ongoing maintenance, while missing security scanning and unpinned workflow actions add hygiene concerns.
56%
Total Score
50
88
100
Only one release exists, published about 1 year and 7 months ago, with no releases in the last 12 months. This provides little evidence of sustained maintenance.
The repository recorded zero commits and zero active maintainers in the last 3 months, which is concerning alongside the single-release history and suggests uncertain ongoing support.
Composer build tooling is present, but no security scanning tools were detected. This is a transparency and maintenance gap, not evidence that the package is unsafe.
The sole workflow was fully analyzed with no dangerous triggers or audit findings, but all 4 action references are unpinned. That leaves avoidable workflow reproducibility and maintenance risk.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
react/socket Version ^1.9 | — | — |
guzzlehttp/psr7 Version ^2.0 || ^1.7 | — | — |
ratchet/rfc6455 Version ^0.3.1 | — | — |
evenement/evenement Version ^3.0 || ^2.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.