Risky to adopt as a dependable production dependency: it has had no release or commit activity for about two years and nine months, with only eight stars and one publisher. It is not deprecated or archived and includes a README and MIT declaration, but the maintenance evidence is too weak.
46%
Total Score
25
79
75
The latest release was published about two years and nine months ago, with no releases in the last 12 months. Although the package accumulated eight releases, the current lack of release activity raises abandonment risk.
The repository recorded zero commits and zero active maintainers in the last three months, providing no evidence of ongoing maintenance. This is consistent with the stale release history and materially weakens confidence in future fixes.
Only one registry account has publish access, which creates a thin publishing base. The linked repository is user-owned rather than organization-backed, so no provided signal compensates for the limited maintainer redundancy.
The repository has only 8 stars, 0 forks, and 1 watcher. Popularity is not decisive by itself, but these very small adoption signals provide little supporting evidence for project maturity or maintenance capacity.
The repository has no security policy, leaving no documented channel or process for reporting vulnerabilities. This is a transparency gap for a package that provides network port-mapping functionality.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
workerman/channel Version * | — | — |
workerman/workerman Version ^4.1 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.