Package Health

phpolar/csrf-protection

A stable release line, recent publication, repository tests, and a security policy provide useful support. Unpinned workflow actions, inherited secrets, and no commits in the last three months leave meaningful maintenance and automation concerns.

Latest 3.2.2PackagistPackagist

65%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

75

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

100

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

100

Health Score Breakdown

Repo commit activitycaution

The repository had no commits and no active maintainers in the last three months. Although a recent release partly offsets this, the current maintenance pause is a genuine caution.

Workflow auditcaution

All nine analyzed action references are unpinned, and high-confidence secrets-inherit findings appear across several workflows; three workflows also grant top-level write access. No untrusted checkout or script-injection findings were reported, so this is a workflow-hygiene caution rather than a severe risk.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

Eric Fortmeyer

Direct Dependencies

DependencyLast ReleaseScore
psr/http-message
Version ^2.0
—
—
psr/http-server-handler
Version ^1.0
—
—
psr/http-server-middleware
Version ^1.0
—
—
php-contrib/response-filter
Version ^2.0
—
—
php-common-enums/http-response-code
Version ^1.0.0
—
—

Weekly Downloads

Info

Last Published
9 months ago
Created
3 years ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform