The repository includes tests and release notes, and licensing is clear. Workflow permissions and unpinned actions add maintenance risk, while the single publisher is backed by an organization.
65%
Total Score
67
88
50
The package runs post-install and post-update Composer scripts, which increases installation-time behavior and review needs compared with a package containing no lifecycle scripts.
The package has existed since 2020 and has four releases, but it has had no release in over a year. That suggests slowing maintenance, though the current release is established rather than experimental.
The repository recorded no commits and no active maintainers in the last three months. This is a meaningful maintenance warning, although the latest repository push is more recent than the package release.
There were no new or merged issues or pull requests in the last month, with one issue and one pull request still open. This supports the picture of low current activity but is not evidence of abandonment by itself.
The repository uses Composer and Make, but no security-scanning tooling was detected. That is a modest transparency and maintenance gap, not a severe risk on its own.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
react/promise Version ^3.2 | — | — |
react/event-loop Version ^1.5 | — | — |
wyrihaximus/constants Version ^1.6 | — | — |
react-parallel/event-loop Version ^2.1.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.