Usable with caveats: it is a mature, licensed package with a complete source tree, tests, and recent releases. However, no commits were recorded in the last three months, and the repository lacks a security policy and explicit workflow token permissions.
72%
Total Score
75
100
94
70
A post-install-cmd script runs during installation, which increases installation complexity and deserves review, although the signal does not show that it performs unsafe actions.
Only one account has registry publishing access, which creates publishing continuity risk. The organization-owned repository provides some backing, so this is a caution rather than a severe concern.
No commits and no active maintainers were recorded during the last three months. This is the clearest maintenance concern, although the package had a recent release and one pull request was merged in the last month.
Composer build tooling is present, but no security scanning tools were detected, leaving a security-hygiene gap for a package that launches and communicates with a Node process.
The repository has no security policy. That makes vulnerability reporting and remediation expectations less transparent, especially for a package spanning PHP and Node runtimes.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
psr/log Version ^1.0 || ^2.0 || ^3.0 | — | — |
clue/socket-raw Version ^1.2 | — | — |
symfony/process Version ^3.3 || ^4.0 || ^5.0 || ^6.0 || ^7.0 || ^8.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.