Package Health

middlewares/https

It has clear licensing, useful documentation, repository tests, and a stable major release. The workflow has no audited dangerous findings, though its five action references are unpinned. That leaves maintenance and dependency-integrity concerns for adopters.

Latest v2.1.0PackagistPackagist

62%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

50

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

93

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

50

Health Score Breakdown

Release historycaution

The package has 14 releases since 2016, but none in the last 12 months; its latest release was about 18 months before collection. This indicates a meaningful maintenance slowdown, though the established release history is compensating evidence.

Repo commit activitycaution

The repository recorded zero commits and zero active maintainers in the last 3 months. This supports the broader evidence of currently inactive maintenance, despite the repository remaining available and unarchived.

Security policycaution

The linked repository has no security policy. For a middleware package handling transport-security behavior, this is a transparency and vulnerability-reporting gap.

Workflow auditcaution

All 5 analyzed action references are unpinned, which weakens build reproducibility and supply-chain hygiene. The audit found no dangerous triggers, untrusted checkouts, script injection, or high-confidence findings, so this remains a caution rather than a severe risk.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

No maintainer information available.

Direct Dependencies

DependencyLast ReleaseScore
middlewares/utils
Version ^2 || ^3 || ^4
—
—
psr/http-server-middleware
Version ^1
—
—

Weekly Downloads

Info

Last Published
1 year ago
Created
9 years ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform