Package Health

reactphp-x/stream-to-stream

Tests, a clear README, MIT licensing, and organization backing provide useful adoption support. The package has little operating history and lacks repository security-policy and scanning signals.

Latest v1.0.0PackagistPackagist

32%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

75

Dependencies
Dependencies
Evaluates the health and security of package dependencies

100

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

78

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

75

Health Score Breakdown

Name lookalikedanger

The package explicitly borrows the identity of the much more established react/stream, with 0.0 artifact overlap but borrows_lookalike_identity=true and no self-described fork. Consumers most likely wanted react/stream, making this a severe supply-chain and adoption risk.

Release historycaution

This is a 499-day-old package with only one release and no releases in the last 12 months. That limited history provides little evidence of sustained maintenance.

Repo commit activitycaution

The repository recorded 0 commits and 0 active maintainers in the last 3 months. Combined with the single-release history, this indicates weak recent maintenance activity.

Repo toolingcaution

Composer build tooling is present, but no security scanning tools were detected. That leaves a modest verification gap for a package with limited maintenance evidence.

Security policycaution

The linked repository has no security policy. This is a transparency and response-process gap, though it is less serious than the identity and maintenance concerns.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

wpjscc

Direct Dependencies

DependencyLast ReleaseScore
react/stream
Version ^1.4
react/promise
Version ^3.2

Weekly Downloads

Info

Last Published
1 year ago
Created
1 year ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform