The project has tests, release notes for this version, and matching MIT licensing. Composer install scripts, broad workflow tokens, and unpinned actions add maintenance and build-hygiene concerns, while recent repository activity is absent.
61%
Total Score
50
88
50
The package runs post-install and post-update Composer scripts. These scripts increase installation complexity and supply-chain exposure, even though their presence alone does not show harmful behavior.
The package has only five releases since February 2019, with no release in the last 12 months and a median interval of about 451 days. This indicates a slow maintenance cadence, though the project is not extremely young.
The repository recorded zero commits and zero active maintainers in the last three months. That is a meaningful sign of currently limited maintenance activity, despite the repository not being archived.
The project uses Make and Composer build tooling, but no security scanning tools were detected. This is a modest transparency and maintenance gap rather than evidence of an unsafe release.
The repository has no security policy. That reduces transparency about vulnerability reporting and response expectations.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
react/cache Version ^1.1 | — | — |
react/promise Version ^2.8 || ^3.1 | — | — |
wyrihaximus/ticking-promise Version ^3.1 | — | — |
wyrihaximus/react-mutex-contracts Version ^2.2 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.