It includes tests, a license, and a source repository that matches the package. The workflow has no detected dangerous findings, but its action references are unpinned and the repository has no security policy.
65%
Total Score
50
90
50
The package has had no releases in about 15 months, despite being nearly five years old. Its nine-release history shows it reached a stable release, but the current gap lowers confidence in ongoing maintenance.
The repository recorded no commits and no active maintainers in the last three months. The June 2025 release provides some recent provenance, but current maintenance capacity is not demonstrated.
The linked repository has no security policy. For a middleware package that handles application asset requests, this is a transparency gap, although it is not evidence of unsafe behavior by itself.
The sole workflow was fully analyzed with no dangerous triggers, untrusted checkouts, script injection, or audit findings. Both action references are unpinned, which weakens build reproducibility, while the absence of a top-level permissions block is acceptable on its own.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
psr/container Version ^1.0||^2.0 | — | — |
psr/http-message Version ^1.0 | — | — |
symfony/polyfill-php80 Version ^1.23 | — | — |
laminas/laminas-diactoros Version ^2.26 || ^3.6 | — | — |
psr/http-server-middleware Version ^1.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.