The package has had no release or repository activity for about eight years, and the assessed alpha version is newer than the registry's recorded latest version. It has a license, tests, documentation, and no install scripts, but the linked repository does not identify the package in its README.
32%
Total Score
50
50
64
75
The last release was about eight years ago, with no releases in the past 12 months; this is a substantial abandonment risk for a middleware dependency.
The repository has had zero commits and zero active maintainers in the past three months, consistent with the long release gap and weak ongoing maintenance.
Five runtime dependencies create a meaningful maintenance surface for this small middleware package, including older framework-related components; no provided signal shows that this dependency burden is actively managed.
The repository name does not match the package name and its README does not mention the package, so ownership of the published package is not clearly demonstrated.
The repository uses Composer, but no security scanning tools are present. This is a transparency and maintenance gap, though the absence of workflows limits the practical impact.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
roave/security-advisories Version dev-master | — | — |
http-interop/http-middleware Version 0.5.0 | — | — |
zendframework/zend-diactoros Version 1.6.1 | — | — |
zendframework/zend-expressive-template Version 1.0.4 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.