This is a promising but very new package with solid engineering and repository hygiene: it is MIT-licensed, has tests, a substantial README, a complete-looking source tree, no install-time lifecycle scripts, active CI/security tooling, and no deprecation or archive status. However, it has only 32 days of history and two releases, with just three commits in the last three months from a single contributor holding 100% of recent commit share; that limited maintenance depth is the main adoption risk. The absent security policy and one workflow with top-level write permissions are additional transparency and CI-governance cautions, though the workflows show no analyzed dangerous patterns. Overall, it appears usable for evaluation or controlled adoption, but should be monitored before becoming a critical dependency.
72%
Total Score
50
100
89
80
Only one registry account has publish access. This is a limited publishing base, and the user-owned repository context does not provide organizational backing to offset that concentration.
The repository is owned by an individual user rather than an organization, so there is no provided evidence of institutional maintenance or succession support.
The package is only 32 days old with two releases and a 32-day median interval, so its long-term maintenance and maturity are not yet demonstrated.
One contributor made all three commits in the last three months, creating a high single-maintainer dependency with no demonstrated handoff capacity.
Only three commits occurred in the last three months, all from one active maintainer. The repository is not inactive, but the low volume and concentration reduce confidence in ongoing maintenance capacity.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
psr/log Version ^3.0 | — | — |
phrity/websocket Version ^3.7.3 | — | — |
guzzlehttp/guzzle Version ^7.15.2 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.