Package Health

lcobucci/content-negotiation-middleware

The source repository still receives pull requests and has comprehensive tests, while the release includes clear notes and PHP 8.3 support. Nearly three years without a new registry release, no commits in three months, and 25 unpinned workflow actions reduce confidence in ongoing maintenance and build reproducibility.

Latest 3.2.0PackagistPackagist

68%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

75

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

92

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

75

Health Score Breakdown

Release historycaution

The latest release was nearly three years ago, with no releases in the last 12 months; this is a meaningful maintenance concern even though the package has a multi-year history and ten releases.

Repo commit activitycaution

The repository has recorded no commits and no active maintainers in the last three months, which weakens evidence of continued maintenance despite recent pull-request activity elsewhere.

Security policycaution

The repository has no security policy and no security-scanning tooling was detected, leaving disclosure and security-maintenance practices less transparent.

Workflow auditcaution

All 25 analyzed action references are unpinned, reducing build reproducibility; however, all six workflows were analyzed, no untrusted checkout or script-injection paths were found, and there were no high- or medium-severity findings.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

Luís Cobucci

Direct Dependencies

DependencyLast ReleaseScore
psr/http-factory
Version ^1.0.2
psr/http-message
Version ^1.1 || ^2.0
fig/http-message-util
Version ^1.1.5
psr/http-server-middleware
Version ^1.0.2

Weekly Downloads

Info

Last Published
2 years ago
Created
8 years ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform