Documentation, tests, licensing, and organizational ownership provide a solid foundation. The single release and absent recent commits limit confidence in ongoing maintenance, while workflow references remain unpinned.
65%
Total Score
75
100
88
75
This release is the package's only release, published 559 days ago, with no releases in the last 12 months. That is a meaningful maintenance concern despite the package not being deprecated.
The repository recorded no commits and no active maintainers in the last three months, and its latest push coincides with the sole release. This weakens evidence of ongoing maintenance.
Composer build tooling is present, but no security-scanning tooling was observed. The missing scanner is a modest transparency gap, not evidence of abandonment.
The repository has no security policy. This leaves vulnerability-reporting expectations unclear, though the package's licensing, tests, and documentation compensate for some transparency concerns.
The sole workflow has no dangerous triggers, untrusted checkouts, injection findings, or write permissions, but all 3 analyzed action references are unpinned. That is a supply-chain hygiene gap without a demonstrated exploit path.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
react/stream Version ^1.4 | — | — |
clue/term-react Version ^1.0 || ^0.1.1 | — | — |
clue/utf8-react Version ^1.0 || ^0.1 | — | — |
react/event-loop Version ^1.2 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.