The repository is backed by an organization, includes tests, and has a matching README and MIT license. However, the package has had no release or commits for about three years, remains an alpha, and uses three unpinned workflow actions.
54%
Total Score
75
86
50
The latest release was on September 18, 2023, with no releases in the last 12 months. That long pause materially raises abandonment risk despite the package's earlier release history.
There were zero commits and zero active maintainers in the last three months, consistent with the roughly three-year release gap. This is a substantial maintenance concern.
The repository has no security policy. That reduces transparency for reporting vulnerabilities, though it is less serious than the absence of maintenance activity.
The assessed release is still marked alpha, and 11 of the 12 recent releases were prereleases. This indicates limited stability for a library dependency.
The workflow audit completed cleanly with no dangerous triggers, sinks, or audit findings. However, all 3 of 3 action references are unpinned, leaving a supply-chain hygiene gap.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
nikic/fast-route Version ~0.7.0 | — | — |
psr/http-message Version <1.1 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.