Is Promise Safe?
Promise — Nerq Trust Score 80.2/100 (B+ grade). Based on analysis of 2 trust dimensions, it is considered safe to use. Last updated: 2026-04-02.
Yes, Promise is safe to use. Promise is a PHP package with a Nerq Trust Score of 80.2/100 (B+), based on 3 independent data dimensions. It is recommended for production use. Security: 90/100. Popularity: 100/100. Data sourced from packagist.org, GitHub, and NVD. Last updated: 2026-04-02. Machine-readable data (JSON).
Is Promise safe?
YES — Promise has a Nerq Trust Score of 80.2/100 (B+). It meets Nerq's trust threshold with strong signals across security, maintenance, and community adoption. Recommended for production use — review the full report below for specific considerations.
What is Promise's trust score?
Promise has a Nerq Trust Score of 80.2/100, earning a B+ grade. This score is based on 2 independently measured dimensions including security, maintenance, and community adoption.
What are the key security findings for Promise?
Promise's strongest signal is popularity at 100/100. No known vulnerabilities have been detected. It meets the Nerq Verified threshold of 70+.
What is Promise and who maintains it?
| Author | react |
| Category | packagist |
| Stars | 2,470 |
| Source | N/A |
Promise Across Platforms
Same developer/company in other registries:
Similar Packagist by Trust Score
Safety Guide: Promise
What is Promise?
Promise is a PHP package — A lightweight implementation of CommonJS Promises/A for PHP.
How to Verify Safety
Run composer audit. Check packagist.org.
You can also check the trust score via API: GET /v1/preflight?target=react/promise
Key Safety Concerns for PHP packages
When evaluating any PHP package, watch for: dependency vulnerabilities, PHP compatibility.
Trust Assessment
Promise has a Nerq Trust Score of 80/100 (B+) and meets Nerq trust threshold. This score is based on automated analysis of security, maintenance, community, and quality signals.
Key Takeaways
- Promise has a Trust Score of 80/100 (B+).
- Recommended for use — passes trust threshold.
- Always verify independently using the Nerq API.
Frequently Asked Questions
Is Promise safe to use?
What is Promise's trust score?
What are safer alternatives to Promise?
Does Promise have known vulnerabilities?
How actively maintained is Promise?
Popular in packagist
Disclaimer: Nerq trust scores are automated assessments based on publicly available signals. They are not endorsements or guarantees. Always conduct your own due diligence.