The package includes tests, a matching MIT license, and no install-time scripts. It is young and still on the 0.x line, so long-term compatibility and maintenance remain less proven.
68%
Total Score
83
79
75
The package is only 105 days old with eight releases, showing active early development but limited evidence of long-term maintenance.
All 12 recent commits came from one contributor, creating a real continuity risk; organization ownership provides some handoff capacity but no second active contributor is shown.
Composer build tooling is present, but no security-scanning tooling was detected, leaving security hygiene less demonstrable.
The repository has no security policy, reducing transparency about vulnerability reporting and response.
Version 0.1.54 is not a stable major release, so compatibility expectations are weaker even though it is not marked as a prerelease.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
psr/http-message Version ^2.0 | — | — |
runopencode/stream Version ^0.1.54 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.