The project has a clear license, tests, release notes, and a stable six-year history. Its security policy is missing, workflow dependencies are not pinned, and recent repository activity is quiet.
70%
Total Score
75
100
100
75
There were no commits and no active maintainers in the last three months. Although a recent release and push provide some compensating evidence, the short-term development lull lowers confidence in ongoing maintenance.
No repository security policy was found. For a network-facing MQTT client, the absence of documented vulnerability-reporting guidance is a real transparency gap.
All two workflows were analyzed with no audit findings or untrusted checkout and script-injection sinks. However, all five action references are unpinned, which weakens build reproducibility, and one workflow grants top-level write access without a corroborating untrusted sink.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
psr/log Version ^1.1|^2.0|^3.0 | — | — |
myclabs/php-enum Version ^1.7 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.