Recent repository activity is not reflected in the three-month commit window, and only two releases were published in the last year. Licensing, repository tests, release notes, and a matching source repository provide useful transparency.
68%
Total Score
50
50
79
67
The package declares 11 runtime dependencies for a runtime OpenAPI middleware library, a meaningful dependency surface but not by itself evidence of poor health.
The package has 22 releases over 703 days, but only 2 releases in the last 12 months, indicating a slower release cadence without showing abandonment by itself.
There were 0 commits and 0 active maintainers in the last 3 months. The recent repository push and current release partly offset this, but the measured development activity is thin.
Composer build tooling is present, but no security scanning tools were detected. This is a hygiene gap rather than evidence that the package is unsafe to depend on.
The repository has no security policy, reducing transparency for reporting and handling vulnerabilities, though this alone does not indicate abandonment.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
symfony/yaml Version ^7.2.3 | — | — |
mezzio/mezzio Version ^3.26 | — | — |
psr/http-message Version ^1.0 || ^2.0 | — | — |
rize/uri-template Version ^0.4.1 | — | — |
respect/validation Version ^2.4 || ^3.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.