The organization-backed repository matches the package and includes tests, a README, and a clear MIT license. Release activity stopped about eight years ago, while repository commits stopped about three years ago; security tooling and a security policy are also absent.
58%
Total Score
50
81
50
The package has made no release in the last 12 months, and its latest registry release was in September 2018. This materially raises maintenance and compatibility risk for a dependency.
There were zero commits and zero active maintainers in the last three months, with the last repository push in February 2023. The long inactivity raises abandonment risk even though the repository is not archived.
Composer build tooling is present, but no security scanning tools were detected. This is a modest transparency and maintenance gap rather than a severe risk by itself.
The repository has no security policy. For a small middleware package this is a genuine process gap, although the available repository and package evidence provides some compensating transparency.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
middlewares/whoops Version ^1.1 | — | — |
thecodingmachine/funky Version ^1 | — | — |
thecodingmachine/middleware-list-universal-module Version ^1.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.