A fast and composable middleware router inspired in Express.js
54%
Total Score
0
70
50
The package has only 4 releases, with none in the last 12 months; its latest release was over 5 years ago. This strongly lowers confidence in ongoing maintenance.
The repository recorded 0 commits and 0 active maintainers in the last 3 months, with the last push more than 5 years ago. This is strong evidence that maintenance has stopped.
The repository has no security policy, leaving vulnerability reporting and response expectations undocumented. This is a transparency gap for a library intended for production use.
Version 0.3.1 is not a stable major release, so compatibility guarantees are limited. The published release notes and documented release-cycle policy provide some compensating transparency.
The single workflow was fully analyzed with no dangerous triggers or audit findings, but all 9 action references are unpinned. That leaves avoidable supply-chain drift risk in CI.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
legatus/http-errors Version ^0.1.0 | — | — |
psr/http-server-middleware Version ^1.0 | — | — |
mnavarrocarter/path-to-regexp-php Version ^1.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.