Package Health

react-parallel/runtime

The repository includes tests and release notes, and licensing is clear. Workflow permissions and unpinned actions add maintenance risk, while the single publisher is backed by an organization.

Latest 3.1.0PackagistPackagist

65%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

67

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

88

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

50

Health Score Breakdown

Lifecycle scriptscaution

The package runs post-install and post-update Composer scripts, which increases installation-time behavior and review needs compared with a package containing no lifecycle scripts.

Release historycaution

The package has existed since 2020 and has four releases, but it has had no release in over a year. That suggests slowing maintenance, though the current release is established rather than experimental.

Repo commit activitycaution

The repository recorded no commits and no active maintainers in the last three months. This is a meaningful maintenance warning, although the latest repository push is more recent than the package release.

Repo issue activitycaution

There were no new or merged issues or pull requests in the last month, with one issue and one pull request still open. This supports the picture of low current activity but is not evidence of abandonment by itself.

Repo toolingcaution

The repository uses Composer and Make, but no security-scanning tooling was detected. That is a modest transparency and maintenance gap, not a severe risk on its own.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

Cees-Jan Kiewiet

Direct Dependencies

DependencyLast ReleaseScore
react/promise
Version ^3.2
—
—
react/event-loop
Version ^1.5
—
—
wyrihaximus/constants
Version ^1.6
—
—
react-parallel/event-loop
Version ^2.1.0
—
—

Weekly Downloads

Info

Last Published
1 year ago
Created
6 years ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform