It has a clear MIT license, a useful README, repository tests, and a changelog. However, the release line has seen no releases or repository activity since June 2020, making ongoing fixes unlikely. Workflow dependencies are also unpinned.
38%
Total Score
50
63
67
The package has had no releases in the last 12 months, and its latest release was in June 2020, roughly six years ago. This is strong evidence that maintenance has stopped.
The repository recorded no new issues, closed issues, pull requests, or merged pull requests in the measured month. Combined with the old release and push dates, this supports a conclusion of inactive maintenance.
The repository is not archived, which avoids a definitive abandonment marker, but it was last pushed in May 2020 and does not offset the stale release history.
The repository has no security policy. For a WebSocket server handling application traffic, this reduces transparency and makes vulnerability reporting less clear.
The single analyzed workflow has no dangerous triggers or audit findings, but all 3 action references are unpinned. That leaves build automation exposed to unexpected upstream changes.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
react/dns Version ^1.1 | — | — |
cboden/ratchet Version ^0.4.1 | — | — |
clue/buzz-react Version ^2.5 | — | — |
guzzlehttp/psr7 Version ^1.5 | — | — |
illuminate/http Version 5.8.*|^6.0|^7.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.