Usable with caveats: the release is well documented, licensed, and backed by an active-looking organization repository, but it is brand new with only one registry release and no recorded commits in the last three months. Review the project before adopting it for critical workloads, especially because its security process is limited.
65%
Total Score
88
100
83
80
The package is only 0 days old and has one release, so there is not yet enough release history to demonstrate sustained maintenance or compatibility stability.
The repository records 0 commits and 0 active maintainers over the last three months. Because the project is newly published, this may reflect limited history rather than abandonment, but it still leaves maintenance continuity unproven.
The repository has 1 star, 0 forks, and 0 watchers. This is weak external adoption evidence, though popularity is only supporting evidence and the project is newly released.
Composer build tooling is present, but no security-scanning tools were detected. The build setup is appropriate, while the missing automated security checks reduce process assurance.
The repository has no security policy, leaving vulnerability-reporting expectations and response procedures undocumented.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
psr/log Version ^1.1 || ^2.0 || ^3.0 | — | — |
react/http Version ^1.10 | — | — |
react/socket Version ^1.16 | — | — |
nesbot/carbon Version ^3.8 || ^2.72 | — | — |
react/promise Version ^3.2 || ^2.11 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.