This is a healthy, established package with over seven years of release history, a current stable release, recent publishing activity, a matching organization-owned repository, repository tests and build/security tooling, and no deprecation or install-time lifecycle scripts. The main concerns are that recent commit activity is limited to one commit from one contributor, the repository lacks a security policy, and its CI workflow does not declare top-level token permissions; these are meaningful hygiene and continuity risks but do not outweigh the package's consistent release and repository evidence. The package artifact omits tests and a changelog, but repository tests and a substantial README compensate for those gaps.
82%
Total Score
80
100
94
80
All recent commits came from one contributor, creating a concentrated short-term bus factor. Because the repository is organization-owned, maintenance can potentially be handed off, which limits but does not eliminate the concern.
The repository recorded 1 commit in the last 3 months from 1 active maintainer. Recent activity exists, but its low volume limits evidence of a strong maintenance cadence.
The repository has 4 stars and 2 forks, indicating limited adoption. Popularity is supporting evidence rather than a verdict, so this is only a minor caution for external validation and community resilience.
No repository security policy was found. This reduces transparency about vulnerability reporting and response procedures, though the presence of security scanning provides partial compensating evidence.
The CI workflow does not declare top-level token permissions. No top-level write permissions were observed, but explicitly declaring least-privilege permissions would provide stronger workflow hygiene.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
psr/http-factory Version ^1.1 | — | — |
psr/http-message Version ^1.1|^2.0 | — | — |
psr/http-server-middleware Version ^1.0.2 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.