Package Health

tourze/psr15-static-file-request-handler

The project includes tests, a license, and a matching repository, but its README is effectively empty and workflow actions are unpinned. Ongoing repository activity helps, though the one-release history remains a meaningful adoption concern.

Latest 0.0.1PackagistPackagist

61%

Total Score

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

75

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

75

Health Score Breakdown

Package scaffoldingcaution

Tests are present and the exact release has GitHub release notes, but the published README contains only one character, leaving consumers without meaningful package guidance.

Release historycaution

This package has only one release, 0.0.1, published about 17 months ago, with no releases in the last 12 months. That leaves limited evidence of release maturity and ongoing maintenance.

Security policycaution

The repository has no security policy. This is a transparency and maintenance gap, although it is less severe for a small package with no reported workflow audit findings.

Version stabilitycaution

Version 0.0.1 indicates an early-stage API even though it is not marked as a prerelease. The lack of a stable major version increases compatibility uncertainty.

Workflow auditcaution

Both workflows were analyzed with no injection, untrusted checkout, permission, or severity findings, and one workflow scopes read-only permissions. However, all three action references are unpinned, reducing build reproducibility and supply-chain hygiene.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

No maintainer information available.

Direct Dependencies

DependencyLast ReleaseScore
nyholm/psr7
Version ^1.8.2
psr/http-message
Version ^1.1 || ^2.0
symfony/filesystem
Version ^6.4
psr/http-server-handler
Version ^1.0
league/mime-type-detection
Version ^1.0

Weekly Downloads

Info

Last Published
1 year ago
Created
1 year ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform