Tests, release notes, and a matching Apache-2.0 license provide useful transparency. The single-maintainer project has no security policy, and its workflow dependencies are unpinned, reducing resilience and build reproducibility.
67%
Total Score
50
94
75
Only one registry account has publish access. With the repository owned by a user rather than an organization, this indicates a thin publishing and continuity base.
The repository recorded zero commits and zero active maintainers in the last three months. Although a release was published recently, the lack of recent commit activity is a meaningful maintenance concern.
The repository has zero stars and forks and one watcher, indicating little visible adoption. Popularity is supporting evidence only, so this modestly lowers confidence in project maturity rather than determining the verdict.
The repository has no security policy. This does not show a security defect, but it reduces transparency about how maintainers receive and handle vulnerability reports.
The single workflow was fully analyzed with no reported audit findings or untrusted execution paths. However, all 3 action references are unpinned, which weakens build reproducibility and supply-chain traceability.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
psr/container Version ^2.0 | — | — |
nikic/fast-route Version ^1.3 | — | — |
laminas/laminas-diactoros Version ^3.8 | — | — |
psr/http-server-middleware Version ^1.0 | — | — |
laminas/laminas-httphandlerrunner Version ^2.1 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.