Usable with caveats: it is an established, licensed package backed by an organization, with tests and a recent release. However, no commits were recorded in the last three months, and the repository lacks security scanning and explicit workflow token permissions.
68%
Total Score
67
100
94
75
The repository recorded zero commits and zero active maintainers over the last three months. This conflicts with the recent release and August push, but still indicates currently quiet development.
There are no open issues and four open pull requests, with no issues or pull requests merged in the last month. The absence of issue backlog is positive, but the unmerged pull requests suggest limited recent activity.
Composer and Box provide build tooling, but no security scanning tools were detected. This is a transparency and maintenance gap for a packaged application.
The repository has no security policy, leaving vulnerability-reporting expectations undocumented.
Both analyzed workflows lack top-level token permissions declarations. No workflow requests top-level write access, which limits the concern, but explicit least-privilege configuration is still absent.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
react/zmq Version ^0.4.0 | — | — |
react/react Version ^1.4 | — | — |
react/socket Version ^1.16 | — | — |
cboden/ratchet Version ^0.4.4 | — | — |
monolog/monolog Version ^1.17 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.