InertiaJS server-side adapter for PSR-7 and PSR-15 applications
68%
Total Score
50
100
88
50
The manifest declares BSD-3-Clause, while the artifact license file is recognised as MIT; this mismatch creates avoidable licensing uncertainty despite a license file being present.
No commits and no active maintainers were recorded during the last three months. The recent release partly offsets this because it was published on the same day as the last repository push, but ongoing maintenance is not yet demonstrated.
Composer build tooling is present, but no security scanning tool is configured, leaving a modest transparency and maintenance gap.
The repository has no security policy. This does not show a security defect, but it weakens the project's documented process for handling vulnerabilities.
The single workflow was fully analyzed, uses read-only permissions, and has no dangerous triggers or audit findings. However, all 4 of its action references are unpinned, which weakens build reproducibility and supply-chain hygiene.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
psr/container Version ^1.0 || ^2.0 | — | — |
psr/http-factory Version ^1.1 | — | — |
fig/http-message-util Version ^1.1 | — | — |
sirix/container-resolver Version ^1.0 | — | — |
psr/http-server-middleware Version ^1.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.