The project has a clear README, tests, release notes, and MIT licensing. Its workflow has no detected dangerous findings, but missing security scanning and unpinned actions leave modest maintenance and build-hygiene concerns.
55%
Total Score
67
71
75
The latest registry release was published in October 2018, with no releases in the last 12 months. That is a substantial freshness concern for a dependency, although the linked repository was pushed more recently.
The repository had zero commits and zero active maintainers in the last three months. Although it was pushed in January 2026, the recent inactivity weakens confidence in ongoing maintenance.
There were no new or closed issues and no new or merged pull requests during the last month, while 22 issues and 9 pull requests remain open. This indicates limited recent project activity.
Composer is used for builds, but no security-scanning tools were detected. The missing scanning is a modest transparency and maintenance gap rather than evidence of an unsafe release.
The repository has no security policy. This makes vulnerability reporting and response expectations less transparent, though it does not by itself show that the package is unmaintained.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
react/stream Version ^1.0 || ^0.7 || ^0.6 || ^0.5 || ^0.4 | — | — |
react/promise Version ~2.2 | — | — |
react/event-loop Version ^1.0 || ^0.5 || ^0.4 | — | — |
evenement/evenement Version ^3.0 || ^2.0 | — | — |
react/promise-stream Version ^1.1 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.