The package is clearly documented, licensed, and has a reasonably focused dependency set. Its security policy is absent, and the single-person publishing setup leaves long-term support unproven.
58%
Total Score
50
100
86
88
Only one account has registry publishing access. That is a thin operational base for a new framework, although it does not by itself show whether source development is shared.
The package is less than a day old with five releases clustered within about 35 minutes, so there is not yet enough history to demonstrate sustained maintenance or release stability.
No commits or active maintainers were recorded in the past three months. The very recent repository push and release history partly explain this for a package published less than a day ago, but they do not establish ongoing maintenance.
The repository has no security policy. For a framework handling HTTP, sessions, databases, queues, and long-running processes, this reduces transparency about vulnerability reporting and response.
The current release is a non-stable 0.x version, which matches the package's early-stage status and means API compatibility is not yet assured.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
workerman/workerman Version ^5.1 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.