It includes a substantial README, tests, release notes, and a matching repository. The project is young and has little public adoption, while lacking a security policy and automated scanning.
82%
Total Score
100
83
50
The repository has zero stars and one fork, indicating little public adoption. Popularity is supporting evidence only, so this lowers confidence in maturity without outweighing the active release and commit history.
Composer build tooling is present, but no security-scanning tool was detected. For a package exposing authentication and WebSocket functionality, that is a modest maintenance-hygiene gap.
The repository has no security policy, leaving reporting and response expectations undocumented for a package that handles tokens and network connections. This is a transparency gap, though not evidence of abandonment.
The single workflow was fully analyzed with no dangerous triggers, untrusted checkouts, or audit findings, but all four action references are unpinned. Unpinned actions weaken build reproducibility and supply-chain hygiene without making the release unfit.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
react/socket Version ^1.14 | — | — |
guzzlehttp/psr7 Version ^2.0 | — | — |
illuminate/http Version ^12.0|^13.0 | — | — |
ratchet/rfc6455 Version ^0.4 | — | — |
firebase/php-jwt Version ^6.10|^7.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.