It has clear licensing, useful documentation, repository tests, and a stable major release. The workflow has no audited dangerous findings, though its five action references are unpinned. That leaves maintenance and dependency-integrity concerns for adopters.
62%
Total Score
50
93
50
The package has 14 releases since 2016, but none in the last 12 months; its latest release was about 18 months before collection. This indicates a meaningful maintenance slowdown, though the established release history is compensating evidence.
The repository recorded zero commits and zero active maintainers in the last 3 months. This supports the broader evidence of currently inactive maintenance, despite the repository remaining available and unarchived.
The linked repository has no security policy. For a middleware package handling transport-security behavior, this is a transparency and vulnerability-reporting gap.
All 5 analyzed action references are unpinned, which weakens build reproducibility and supply-chain hygiene. The audit found no dangerous triggers, untrusted checkouts, script injection, or high-confidence findings, so this remains a caution rather than a severe risk.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
middlewares/utils Version ^2 || ^3 || ^4 | — | — |
psr/http-server-middleware Version ^1 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.