The repository has tests, a changelog, MIT licensing, and Psalm scanning, while its organization backing and clear package match add useful transparency. Workflow references are unpinned, so future builds have weaker reproducibility.
58%
Total Score
67
100
94
50
The package has 16 releases since January 2019, but none in the last 12 months and its latest release was over two years ago. This indicates materially slowed maintenance despite a previously established release history.
There were zero commits and zero active maintainers in the last three months, consistent with the latest release being over two years old. This raises the risk that defects or compatibility changes will not be addressed promptly.
There were no new or closed issues and no pull-request activity in the last month, with three issues remaining open. This supports the broader evidence of currently limited maintenance.
The repository has no security policy, leaving the vulnerability-reporting process unclear. This is a transparency gap, but not a severe dependency risk on its own.
The single workflow was fully analyzed with no dangerous triggers, untrusted checkouts, or audit findings. However, all 7 action references are unpinned, which weakens build reproducibility and update control.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
amphp/amp Version v2.6.* | — | — |
amphp/socket Version v1.2.* | — | — |
phpinnacle/buffer Version v1.2.* | — | — |
evenement/evenement Version v3.0.* | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.