The package includes tests, a changelog, a clear license, and recent release activity. Maintenance is concentrated in one contributor, and its single workflow uses one unpinned action. The repository is active and not archived.
82%
Total Score
75
100
94
83
The repository is owned by an individual rather than an organization, so the single-maintainer concentration is not buffered by visible organizational backing. Recent commits and releases still show that the project is actively maintained.
One contributor made all 29 commits in the last 3 months, giving the project a complete single-maintainer concentration. The active repository offsets abandonment concerns but does not remove succession risk.
Composer build tooling is present, but no security scanning tool was detected. This is a modest repository-hygiene gap, not a severe risk on its own.
The repository has no security policy. For a small middleware package this is a transparency gap, though active maintenance and clear project structure provide some compensation.
The workflow was fully analyzed, uses read-only permissions, and has no untrusted-trigger sinks or audit findings. Its one action reference is unpinned, which is a supply-chain hygiene weakness but not a severe risk alone.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
ctw/ctw-http Version ^5.0 | — | — |
psr/container Version ^1.0 || ^2.0 | — | — |
psr/http-message Version ^1.1 || ^2.0 | — | — |
middlewares/utils Version ^4.0.2 | — | — |
ctw/ctw-middleware Version ^5.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.