The package is clearly documented, licensed, released regularly, and backed by an organization with repository tests. Its small public footprint and limited security process leave less evidence of long-term resilience.
62%
Total Score
67
100
86
67
The repository recorded zero commits and zero active maintainers during the last three months, a meaningful sign that maintenance may have slowed despite the recent release history.
Only one issue is open, with no new or closed issues or pull requests in the last month. This is limited activity but not enough alone to establish abandonment.
The repository uses Composer and Make, but no security scanning tools were detected. That weakens automated security assurance without proving a supply-chain problem.
No security policy was found in the repository, leaving vulnerability-reporting expectations and response procedures unclear.
Version 0.1.7 is not a stable major release, so its API may still change; however, it is not marked prerelease and recent releases are consistently non-prerelease.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
amphp/amp Version ^3.1 | — | — |
amphp/pipeline Version ^1.2 | — | — |
amphp/postgres Version ^2.1 | — | — |
thesis/time-span Version ^0.2.3 | — | — |
revolt/event-loop Version ^1.0.7 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.