server-timing is a package that contains a middlware for adding Server-Timing information to your responses
65%
Total Score
caution
Usable with caveats: no recent commits and weak workflow hygiene limit confidence.
The package has only two releases since December 2019, with no releases in the last 12 months and the latest release about 17 months ago. This indicates a slow maintenance cadence, although the current version is stable.
There were no commits and no active maintainers in the last three months. Combined with the long release interval, this is evidence of limited current maintenance capacity.
Composer is used as the build tool, but no security scanning tool was detected. The missing scanner is a hygiene gap rather than evidence that the package is unsafe.
The repository has no security policy. For a web middleware package, this leaves vulnerability reporting and response expectations less transparent.
The sole workflow was fully analyzed with no dangerous triggers or audit findings, but all three action references are unpinned. That leaves avoidable workflow reproducibility and action-supply-chain exposure.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
illuminate/support Version ^12.6 | — | — |
psr/http-server-middleware Version ^1.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.