The project has a clear MIT license, a complete consumer-facing README, dependency scanning, and an organization-backed repository. Recent release activity is present, but no commits or active maintainers were recorded in the last three months; the publish workflow also has high-confidence template-injection findings and all seven action references are unpinned.
62%
Total Score
50
50
94
67
No commits and no active maintainers were recorded in the last three months, indicating recent maintenance has stalled despite the recent release.
The package has 20 runtime dependencies, including several runtime libraries and extensions. That is a meaningful dependency surface, but the provided tooling evidence partially offsets the maintenance risk.
Only one registry account has publish access, which is a narrow release bus factor; the organization-backed repository provides some compensation, so this remains a caution rather than a severe risk.
There is only one open issue and no recent issue or pull-request activity. This is consistent with a quiet project but gives little evidence of active support.
The repository has no security policy, leaving vulnerability-reporting expectations unclear for a telecommunications platform.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
react/http Version ^1.11 | — | — |
rtckit/esl Version ^0.8 | — | — |
rtckit/sip Version ^0.7 | — | — |
ramsey/uuid Version ^4.9 | — | — |
symfony/yaml Version ^6.4 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.