It has clear licensing, tests, release notes, and organization backing. Its age and sparse recent activity make future fixes uncertain, while workflow references are not pinned.
62%
Total Score
75
100
81
75
The package has had no registry release for over five years, despite 15 releases historically; this raises maintenance and abandonment concerns.
There were no commits and no active maintainers in the last three months, indicating that ongoing maintenance is currently sparse.
Composer build tooling is present, but no security scanning tool was detected, leaving a modest repository hygiene gap.
The repository has no security policy, making vulnerability reporting less transparent; the package's small scope limits but does not remove this concern.
Version v0.9.1 is not a stable major release, which adds some compatibility uncertainty, though it is not marked as a prerelease.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
psr/http-server-middleware Version ^1.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.