Websocket client and server for Shelly Gen2+ devices in PHP
65%
Total Score
caution
A stable MIT package is correctly linked, but release and commit activity have gone quiet.
Only one registry account has publishing access. The matching repository is user-owned rather than organization-backed, so there is limited visible publishing continuity if that maintainer becomes unavailable.
The package has 10 releases over about 23 months, but only one release in the last 12 months and the latest was about 6 months ago, indicating a substantially slower cadence.
There were zero commits and zero active maintainers in the last 3 months, consistent with the recent slowdown and raising abandonment risk for a small project.
The repository uses Composer, but no security scanning tools were detected. This is a transparency and maintenance gap, though not evidence of unsafe code by itself.
The repository has no security policy, leaving no documented process for reporting or handling vulnerabilities in a network-facing WebSocket package.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
react/promise Version ^3.2 | — | — |
sharkydog/http Version ^1.2 | — | — |
react/event-loop Version ^1.5 | — | — |
sharkydog/private-emitter Version ^1.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.