Tests, a clear README, and a licensed artifact make the package easy to evaluate and integrate. Maintenance is concentrated in one contributor, while the missing security policy and one unpinned workflow action leave modest operational gaps.
76%
Total Score
75
94
75
All 29 recent commits came from one contributor, giving the project a single-person maintenance dependency. That raises continuity risk for a package without organization ownership shown by the project backing signal.
Composer build tooling is present, but no security scanning tool was detected. The build setup is established, while security-process visibility is limited.
The repository has no security policy. For a small middleware package this is a modest transparency gap, though it does not by itself indicate abandonment or unsafe code.
The only workflow was fully analyzed, uses read-only permissions, and has no reported audit findings. However, its single action reference is unpinned, leaving a modest supply-chain hygiene gap.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
ctw/ctw-http Version ^5.0 | — | — |
psr/container Version ^1.0 || ^2.0 | — | — |
psr/http-message Version ^1.1 || ^2.0 | — | — |
middlewares/utils Version ^4.0.2 | — | — |
ctw/ctw-middleware Version ^5.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.