The repository has tests, release notes, a clear MIT license, and recent pull-request activity. Its small history, no commits in three months, missing security policy, and broad unpinned workflow setup warrant extra maintenance scrutiny.
68%
Total Score
67
50
88
67
Seven runtime dependencies create a meaningful transitive maintenance surface for this small library, though the listed dependencies are directly relevant to its ReactPHP networking role.
post-install-cmd and post-update-cmd scripts add install-time behavior and therefore some supply-chain exposure, although this signal alone does not show that the scripts are unsafe.
The repository is maintained under an individual user account rather than an organization, so the small observed maintenance base carries more weight than it would for an organization-backed project.
The package is about 14 months old with three releases and two releases in the last 12 months; the roughly four-month median interval indicates a modest rather than highly active cadence.
There were no commits and no active maintainers in the last three months, a material sign of a thin or paused maintenance base; recent pull-request activity partly offsets but does not remove it.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
react/dns Version ^1.12 | — | — |
react/socket Version ^1.15 | — | — |
react/stream Version ^1.3 | — | — |
react/promise Version ^2 || ^3 | — | — |
react/event-loop Version ^1.5 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.