Clear documentation, tests, and recent release notes make integration easier. Ongoing releases and organization backing help, but the package lacks licensing and security-policy coverage, with all workflow actions unpinned.
68%
Total Score
83
83
50
No license declaration, license file, or repository license file was detected, leaving the legal terms for using this dependency unclear.
A post-autoload-dump install-time script runs during Composer installation, adding execution behavior that consumers should understand before adoption.
The repository received 9 commits in the last 3 months from one active maintainer, which supports current maintenance but shows limited recent development breadth.
Composer build tooling is present, but no security scanning tools were detected, reducing automated visibility into dependency or code risks.
The repository has no published security policy, so there is no documented process for reporting and handling vulnerabilities.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
react/stream Version ^1.4.0 | — | — |
vulnerar/http Version ^3.1 | — | — |
react/event-loop Version ^1.6.0 | — | — |
laravel/framework Version ^11.0|^12.0|^13.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.