The artifact has a useful README, tests, a GitHub release, and an MIT declaration. There is no security policy or automated security scanning, so maintenance and response practices are less transparent.
52%
Total Score
50
83
75
This package has only one release, with none in the last 12 months, which provides little evidence of an established release cadence or ongoing maintenance.
The repository had no commits and no active maintainers during the last three months, which is a concrete sign of limited ongoing maintenance.
Composer is used for builds, but no security scanning tools are configured, leaving automated detection of dependency or repository issues weaker.
The repository has no security policy, making its vulnerability-reporting and response process less transparent.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
psr/log Version ^3 || ^2 || ^1 | — | — |
react/event-loop Version ^1.0 || ^0.5 || ^0.4.3 | — | — |
evenement/evenement Version ^3.0 || ^2.0 | — | — |
react/promise-timer Version ^1.2.1 | — | — |
voryx/thruway-common Version ^1.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.