This is a generally healthy, established package: it has been maintained since 2020, released 6 times in the last 12 months, is on a stable major version, is not deprecated, and has a matching active source repository with repository tests, Composer tooling, security scanning, and no identified dangerous workflow patterns. The main concerns are concentrated maintenance, with one contributor responsible for all recent commits, very low repository popularity, no repository security policy, and unspecified GitHub Actions token permissions. The artifact is minimal and omits tests and a changelog, but the linked repository contains both, which compensates for those packaging gaps. It appears reasonable to depend on, with normal caution about maintainer concentration and repository security hygiene.
78%
Total Score
80
100
94
80
All recent commits come from one contributor, creating a concentrated maintenance dependency. The organization-owned repository partially mitigates the risk because maintenance can potentially be transferred within the project.
There was 1 commit in the last 3 months from 1 active maintainer. Recent activity exists, but the low volume limits evidence of sustained maintenance capacity.
The repository has only 1 star, 1 fork, and 1 watcher. Low popularity is supporting caution about external adoption and community depth, but it does not outweigh the package's release and maintenance evidence.
No security policy is present in the repository, leaving vulnerability-reporting expectations and response procedures undocumented.
The one workflow lacks top-level token permissions declarations. No write permissions were observed, but explicitly constraining the token would provide stronger CI security hygiene.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
nikic/fast-route Version ^1.3.1|2.0.0-beta1|^2.0 | — | — |
psr/http-message Version ^1.1|^2.0 | — | — |
chubbyphp/chubbyphp-framework Version ^6.1.2 | — | — |
chubbyphp/chubbyphp-http-exception Version ^1.3.4 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.