Package Health

xp-forge/websockets

It has tests, a changelog, a stable current release, and no install-time scripts. Recent repository work is sparse and concentrated, while the workflow uses three unpinned actions and has no published security policy.

Latest v4.3.0PackagistPackagist

68%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

67

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

94

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

83

Health Score Breakdown

Repo bus factorcaution

One contributor made all commits in the last three months. Organization ownership provides some handoff capacity, but no second active contributor is shown to offset the concentration.

Repo commit activitycaution

Only one commit was recorded in the last three months, showing limited recent development activity despite the recent push and current release.

Repo toolingcaution

Composer build tooling is present, but no security scanning tool was detected, leaving a modest transparency and maintenance gap.

Security policycaution

The repository has no published security policy, so vulnerability reporting and response expectations are not documented.

Workflow auditcaution

The sole workflow was fully analyzed with no dangerous triggers, untrusted checkouts, script injection, or audit findings. However, all three action references are unpinned, which weakens build reproducibility.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

No maintainer information available.

Direct Dependencies

DependencyLast ReleaseScore
xp-forge/uri
Version ^3.0 | ^2.0 | ^1.4
—
—
xp-framework/core
Version ^12.0 | ^11.0 | ^10.0
—
—
xp-framework/logging
Version ^11.0 | ^10.0 | ^9.1
—
—
xp-framework/networking
Version ^11.0 | ^10.0 | ^9.3
—
—

Weekly Downloads

Info

Last Published
5 months ago
Created
7 years ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform