Clear documentation, tests, changelog, and licensing make the package straightforward to adopt. The workflow has an unpinned action, and the project lacks a security policy and automated security scanning.
72%
Total Score
67
100
89
83
The repository is owned by an individual user rather than an organization. That makes the single-maintainer concentration more consequential because no organizational handoff capacity is shown.
One contributor made 100% of the 33 commits in the last 3 months. For this user-owned project, that concentration creates a meaningful continuity risk even though recent activity is strong.
The repository has 1 star, 0 forks, and 1 watcher. Popularity is only supporting evidence, but these low numbers provide little independent evidence of broad community support.
Composer build tooling is present, but no security scanning tools were detected. The missing scanning is a modest security-maintenance gap, not evidence that the package is unsafe.
The repository has no security policy. For a small middleware library this is a transparency gap, though it is less serious than missing release or maintenance activity.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
psr/http-message Version ^1.1 || ^2.0 | — | — |
psr/http-server-middleware Version ^1.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.