Package Health

mbretter/stk-csrf

Stk CSRF service and middleware

Latest 1.2.0PackagistPackagist

60%

Total Score

caution

Usable with caveats: no releases or commits since August 2022.

Health Score Breakdown

Maintainerscaution

Only one registry maintainer is listed, and the project is backed by an individual repository owner. This creates a thin maintainer base and increases continuity risk.

Release historycaution

The package has 8 releases since October 2019 but none in the last 12 months; the latest release was in August 2022. This indicates prolonged maintenance inactivity, although the repository is not archived.

Repo commit activitycaution

There were no commits and no active maintainers in the last 3 months, consistent with the long gap since the latest release. This lowers confidence in ongoing maintenance.

Repo toolingcaution

Composer build tooling is present, but no security scanning tools were detected. The package's tests provide some assurance, but they do not replace dependency or vulnerability scanning.

Security policycaution

The linked repository has no security policy, leaving no documented process for reporting or handling vulnerabilities. This is a transparency gap for security-sensitive middleware.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

Michael Bretterklieber

Direct Dependencies

DependencyLast ReleaseScore
mbretter/stk-di
Version >=2
—
—
psr/http-message
Version ^1.0
—
—
tuupola/http-factory
Version ^1.3.0
—
—
psr/http-server-middleware
Version ^1.0
—
—

Weekly Downloads

Info

Last Published
4 years ago
Created
7 years ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform