The repository remains available, includes tests, and has recent pull-request activity. However, this release is about 1,300 days old, with no releases in the last 12 months, and its workflows use broad write permissions and unpinned actions.
62%
Total Score
50
81
50
The package runs post-install and post-update Composer scripts. These add installation complexity, but the signal provides no evidence that the scripts are unsafe or unusually invasive.
The package has had only two releases, both about 1,300 days ago, with no releases in the last 12 months. This makes the assessed release materially stale, although repository activity provides some compensation.
There were zero commits and zero active maintainers in the last three months. A recent push and ongoing pull-request activity partly offset this, but recent implementation activity still appears thin.
The repository uses Make and Composer build tooling, but no security scanning tools were detected. The build setup is positive; the missing scanning coverage is a modest transparency gap.
Version 0.1.1 is not a prerelease, but it remains below a stable major version. The absence of prerelease labeling is positive, while the low major version leaves maturity less established.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
reactivex/rxphp Version ^2.0 | — | — |
react/event-loop Version ^1.3 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.