A clear README, tests, changelog, stable version, and matching repository make the package straightforward to evaluate. Missing security scanning and unpinned workflow actions add maintenance risk, while recent repository activity is limited.
65%
Total Score
83
100
83
75
The package has seven releases since November 2020, but none in the last 12 months and the latest release was December 2024. That long release gap lowers confidence in ongoing maintenance.
There were no commits and no active maintainers in the past three months. The repository's December 2025 push is compensating evidence that it has not been abandoned outright, but current maintenance momentum is still weak.
The repository has no stars and only one fork and watcher. This provides little community support, but popularity is supporting evidence rather than a standalone health verdict.
Composer build tooling is present, but no security scanning tools were detected. For authentication middleware, that is a meaningful transparency and maintenance gap.
The repository has no security policy. For middleware handling authentication tokens, the absence of a documented vulnerability-reporting path is a genuine project hygiene concern.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
psr/log Version ^2 || ^3 | — | — |
psr/http-factory Version ^1.0 | — | — |
dakujem/generic-middleware Version ^1 | — | — |
psr/http-server-middleware Version ^1.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.