Package Health

react/whois

It has an MIT license, tests, a changelog, and a repository that clearly matches the package. The missing security policy adds little assurance for a dependency this old.

Latest v0.2.0PackagistPackagist

15%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

50

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

64

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

75

Using this package? Scan for Free

Health Score Breakdown

Registry deprecationdanger

Packagist marks the entire package as abandoned, with no replacement specified. This is a direct warning against taking a new dependency on the package.

Release historydanger

The latest release was published about 13 years ago, and there have been no releases in the last 12 months. The three-release history indicates the package is not being maintained for current use.

Repo commit activitydanger

The repository recorded no commits and no active maintainers in the last three months, while its last push was about 10 years ago. The linked project therefore provides no evidence of ongoing maintenance.

Repo issue activitycaution

There were no new or closed issues or pull requests in the last month, despite four open issues and three open pull requests. This reinforces the evidence of an inactive project.

Repo toolingcaution

Composer is used as the build tool, but no security scanning tools are present. The missing scanning is a minor assurance gap rather than a standalone reason to reject the package.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

No maintainer information available.

Direct Dependencies

DependencyLast ReleaseScore
react/dns
Version 0.3.*
react/curry
Version 1.0.*
react/socket
Version 0.3.*
react/stream
Version 0.3.*
react/promise
Version ~1.0

Weekly Downloads

Info

Last Published
13 years ago
Created
13 years ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform