The repository has only 2 stars and no security-scanning tool, while its single workflow uses 2 unpinned actions. Readme, tests, release notes, and a security policy provide useful project hygiene.
82%
Total Score
100
100
89
100
The repository has only 2 stars, 0 forks, and 1 watcher, showing a very small public adoption footprint. This is supporting caution rather than evidence of abandonment because release and repository activity are recent.
Composer build tooling is present, but no security-scanning tool was detected. That is a modest transparency and maintenance gap, not a release-blocking issue by itself.
The workflow audit analyzed all 1 workflow, found no untrusted checkouts, script injection, or audit findings, and uses read-only permissions. Both of its 2 action references are unpinned, which weakens build reproducibility.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
psr/log Version ^3.0 | — | — |
quasarstream/mdns Version ^1.0 | — | — |
quasarstream/stun Version ^1.0 | — | — |
quasarstream/turn Version ^1.0 | — | — |
quasarstream/exception Version ^1.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.