Package Health

fetzi/server-timing

server-timing is a package that contains a middlware for adding Server-Timing information to your responses

Latest 1.1.0PackagistPackagist

65%

Total Score

caution

Usable with caveats: no recent commits and weak workflow hygiene limit confidence.

Health Score Breakdown

Release historycaution

The package has only two releases since December 2019, with no releases in the last 12 months and the latest release about 17 months ago. This indicates a slow maintenance cadence, although the current version is stable.

Repo commit activitycaution

There were no commits and no active maintainers in the last three months. Combined with the long release interval, this is evidence of limited current maintenance capacity.

Repo toolingcaution

Composer is used as the build tool, but no security scanning tool was detected. The missing scanner is a hygiene gap rather than evidence that the package is unsafe.

Security policycaution

The repository has no security policy. For a web middleware package, this leaves vulnerability reporting and response expectations less transparent.

Workflow auditcaution

The sole workflow was fully analyzed with no dangerous triggers or audit findings, but all three action references are unpinned. That leaves avoidable workflow reproducibility and action-supply-chain exposure.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

Johannes Pichler

Direct Dependencies

DependencyLast ReleaseScore
illuminate/support
Version ^12.6
—
—
psr/http-server-middleware
Version ^1.0
—
—

Weekly Downloads

Info

Last Published
1 year ago
Created
6 years ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform