The package is focused and well documented, with tests and release notes maintained in the source repository. Its MIT license, organization backing, and non-archived repository support continued use, though workflow references are not pinned.
64%
Total Score
75
100
88
83
The package has existed since 2018 and has eight releases, but the latest release was about 18 months ago and there were no releases in the last 12 months. This indicates slowing maintenance rather than abandonment by itself.
There were no commits and no active maintainers in the last three months, consistent with roughly 18 months since the last repository push. This is the strongest maintenance concern, although the package may be stable and narrowly scoped.
Composer build tooling is present, but no security scanning tools were detected. For a small library this is a modest transparency and hygiene gap.
The repository has no security policy. This weakens vulnerability-reporting transparency, but it is not evidence that the package is unsafe.
The single workflow was fully analyzed with no reported audit findings or dangerous triggers, but all five action references are unpinned. Unpinned actions leave build inputs less reproducible and create a maintenance hygiene concern.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
middlewares/utils Version ^2 || ^3 || ^4 | — | — |
psr/http-server-middleware Version ^1 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.