The repository includes tests, matches the package, and has organization backing. There are no install-time scripts, but security review coverage is limited and the project is still early in its lifecycle.
68%
Total Score
67
81
75
The package is 58 days old with only one release, so there is little evidence of sustained release practice or maturity.
One contributor made all four recent commits. Organization ownership provides some handoff capacity, but no second active contributor is evidenced.
The repository had four commits in the last three months, showing recent activity, but that activity is limited in volume.
Composer build tooling is present, but no security scanning tools are reported, leaving security-process coverage limited.
The repository has no security policy, so its process for reporting and handling vulnerabilities is not documented.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
psr/http-message Version ^1.1 || ^2.0 | — | — |
nexus-actors/http Version ^0.1 | — | — |
psr/http-server-handler Version ^1.0 | — | — |
nexus-actors/observability Version ^0.1 | — | — |
psr/http-server-middleware Version ^1.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.