The source repository includes tests, a matching MIT license, and a workflow audit with no dangerous sinks. Six workflow actions are unpinned, and the project has no security policy or security-scanning tool.
55%
Total Score
50
70
50
This is the only release, published nearly three years ago, with no releases in the last 12 months. That leaves current compatibility and maintenance uncertain.
The repository recorded no commits and no active maintainers in the last three months, consistent with the long release gap. This materially raises abandonment risk.
Composer build tooling is present, but no security-scanning tool was detected. The missing scanning capability modestly reduces supply-chain transparency.
The linked repository has no security policy, reducing transparency about vulnerability reporting and response. This is a hygiene gap rather than evidence of an unsafe release by itself.
The single workflow was fully analyzed with no untrusted checkouts, script injection, or audit findings. However, all six action references are unpinned, leaving avoidable build-integrity exposure.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
psr/log Version ^3.0 | — | — |
psr/clock Version ^1.0 | — | — |
psr/http-message Version ^1.0.1 | — | — |
stefna/ds-collection Version ^1.0 | — | — |
psr/http-server-middleware Version ^1.0.1 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.