The package is licensed, documented, and has a small dependency footprint without install-time scripts. Its repository is not archived, but the absence of activity for more than 11 years and a missing security policy leave substantial maintenance risk.
38%
Total Score
25
50
67
75
The latest release was published in September 2013, and there have been no releases in the last 12 months. This is strong evidence of abandonment for a process-management library.
There were zero commits and zero active maintainers in the last three months, consistent with the repository's last push being more than 11 years ago. This materially raises abandonment risk.
The package has four runtime requirements, including the native pcntl and posix extensions, which narrows portability but does not by itself indicate abandonment or unsafe maintenance.
Only one registry account has publish access. With no recent repository activity or organizational backing shown, the project has limited visible maintenance capacity.
The linked repository is not archived, which is a positive sign, but its last push was in April 2015 and does not offset the prolonged inactivity.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
pagon/eventemitter Version * | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.