Tests, a clear README, MIT licensing, and organization backing provide useful adoption support. The package has little operating history and lacks repository security-policy and scanning signals.
32%
Total Score
75
100
78
75
The package explicitly borrows the identity of the much more established react/stream, with 0.0 artifact overlap but borrows_lookalike_identity=true and no self-described fork. Consumers most likely wanted react/stream, making this a severe supply-chain and adoption risk.
This is a 499-day-old package with only one release and no releases in the last 12 months. That limited history provides little evidence of sustained maintenance.
The repository recorded 0 commits and 0 active maintainers in the last 3 months. Combined with the single-release history, this indicates weak recent maintenance activity.
Composer build tooling is present, but no security scanning tools were detected. That leaves a modest verification gap for a package with limited maintenance evidence.
The linked repository has no security policy. This is a transparency and response-process gap, though it is less serious than the identity and maintenance concerns.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
react/stream Version ^1.4 | — | — |
react/promise Version ^3.2 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.