The repository is active and the package has tests, release notes, a clear license, and organization backing. The registry has had no release in about two years, while all three workflow actions are unpinned and no security policy is published.
72%
Total Score
75
100
88
75
The package has existed since 2014 with 13 releases, but it has had no registry release in about two years; this is a real maintenance concern despite the long project history.
There were no commits and no active maintainers in the last three months, indicating limited recent development activity even though the repository is not archived.
Composer build tooling is present, but no security-scanning tooling was detected; this is a modest transparency and hygiene gap.
The repository has no published security policy, leaving vulnerability reporting and response expectations undocumented.
The single workflow was fully analyzed with no dangerous triggers, untrusted checkouts, script injection, or audit findings. However, all 3 action references are unpinned, which weakens build reproducibility and supply-chain hygiene.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
react/dns Version ^1.13 | — | — |
react/promise Version ^3.2 || ^2.1 || ^1.2 | — | — |
react/event-loop Version ^1.2 | — | — |
evenement/evenement Version ^3.0 || ^2.0 || ^1.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.