The package is clearly licensed, documented, and has a small dependency footprint. Recent release activity helps, but the project lacks tests and a security policy, leaving limited evidence for long-term reliability.
64%
Total Score
50
100
88
75
The registry namespace and repository owner match, but the owner is an individual account, so the signals show no organizational backing.
The package is only 27 days old, although it has already had seven releases and was updated recently. This supports active early development but provides little long-term maintenance history.
All three recent commits came from one contributor, so maintenance depends entirely on a single person. The repository is user-owned rather than organization-owned, providing no shown organizational handoff capacity.
Three commits from one active maintainer in the last three months show some ongoing work, but the small volume offers limited evidence of sustained maintenance.
Composer is used for builds, but no security scanning tool was detected. For security-sensitive CSRF middleware, that leaves a useful assurance gap.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.