The MIT license, tests, changelog, and package-matching repository provide useful transparency. The missing security policy and very small visible project footprint leave limited evidence of ongoing support.
56%
Total Score
50
100
72
83
The repository is owned by a user account rather than an organization. This is compatible with a small open-source project, but it offers less visible backing for long-term maintenance.
This is the only release, published about 2 years and 4 months ago, with no releases in the last 12 months. That is meaningful evidence of limited maintenance for a library dependency.
There were zero commits and zero active maintainers in the last 3 months. Combined with the single-release history, this indicates no recent maintenance capacity.
The repository has zero stars and forks and only one watcher. Popularity is not required for health, but these counters provide little supporting evidence of community adoption.
Composer is used as the build tool, but no security scanning tools were detected. The build setup is appropriate, while security-tooling coverage is limited.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
psr/log Version ^3.0.0 | — | — |
react/socket Version ^1.9 | — | — |
react/event-loop Version ^1.5 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.