It has clear documentation, repository tests, and a stable MIT-licensed release. The project has had no commits in the last three months, and its workflow uses five unpinned actions, limiting confidence in ongoing maintenance.
67%
Total Score
75
100
92
67
The package has existed for about 10 years with 17 releases, but it has had no releases in the last 12 months despite a roughly 58-day historical median interval.
There were no commits and no active maintainers in the last three months. Combined with no registry releases in the last 12 months, this indicates materially slowed maintenance.
The repository has no published security policy. This is a transparency gap for a package that processes application inputs, although it does not prove the project is unsafe.
The sole workflow was fully analyzed with no dangerous triggers or audit findings, but all five action references are unpinned. That weakens build reproducibility and supply-chain hygiene without indicating an immediate severe risk.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
lcobucci/jwt Version ^4 || ^5 | — | — |
imagecow/imagecow Version ^2 | — | — |
middlewares/utils Version ^3.3 | — | — |
psr/http-server-middleware Version ^1 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.