This release appears usable and actively maintained, with 14 releases over 642 days, five releases in the last 12 months, a repository that is not archived, and 38 commits in the last three months. The main concerns are concentrated maintenance in a single active contributor, no tests or changelog in either the artifact or repository, no security scanning or security policy, and a pull-request-target workflow without top-level token permissions. Organization backing and the package/repository name and README alignment provide some mitigation, but the package remains more dependent on one maintainer and has weaker verification and security-process transparency than a highly mature dependency.
72%
Total Score
75
50
78
70
One workflow uses pull_request_target, which can be security-sensitive even though no untrusted checkout or script injection was detected. This warrants review rather than indicating a severe issue on its own.
Seven runtime dependencies, including platform extensions and the event-loop/runtime stack, create a meaningful dependency surface for a scheduler library but are proportionate to its functionality.
The package includes a README, but neither the artifact nor repository contains tests or a changelog. For a runtime scheduler library, the absence of repository tests is a genuine maintenance and regression-risk gap.
All 38 recent commits came from one contributor, creating a clear continuity and bus-factor concern. The organization-owned repository provides some capacity for handoff, but no second active contributor is evidenced.
There were no new or closed issues and no pull requests in the last month. This is ambiguous because it may reflect a quiet project, but it provides little evidence of broader maintenance participation.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
amphp/amp Version ^3.0 | — | — |
revolt/event-loop Version ^1.0 | — | — |
phpstreamserver/core Version ^0.10 | — | — |
dragonmantank/cron-expression Version ^3.4 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.