The package is small and clearly linked to its source, with a stable major release, MIT licensing, and no install-time scripts. Its organization-backed repository is not archived, but the limited release history and absent recent commit activity make long-term maintenance less certain.
60%
Total Score
75
86
100
Only two releases exist, with none in the last 12 months and the latest published about 19 months ago. This is a meaningful maintenance concern, though the package is still relatively small and its repository remains active enough to be present and unarchived.
The repository recorded zero commits and zero active maintainers in the last 3 months, which weakens evidence of ongoing maintenance. The repository was pushed around the latest release, so this indicates inactivity rather than confirmed abandonment.
Composer build tooling is present, but no security scanning tools were detected. This is a modest transparency gap, not a severe risk, because the package has clear source and build structure.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
react/async Version ^4.2 | — | — |
react/promise-timer Version ^1.10 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.