Package Health

wyrihaximus/react-http-middleware-twig

The repository has tests, a usable README, and dependency scanning. Install-time scripts and incomplete workflow hardening add adoption risk, while the unarchived repository and stable release provide limited reassurance.

Latest 2.0.0PackagistPackagist

42%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

50

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

88

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

50

Health Score Breakdown

Release historydanger

The package has had only two releases, with the latest in June 2020 and none in the last six years. The repository is not archived, but the long release gap creates substantial abandonment risk for a dependency.

Lifecycle scriptscaution

The package runs post-install and post-update Composer scripts, which expand installation behavior and deserve scrutiny when depending on a package. No provided signal shows these scripts are harmful, so this is a limited concern.

Repo commit activitycaution

There were no commits or active maintainers in the last three months, despite a recent repository push recorded by the archive signal. This provides weak evidence of ongoing development and lowers maintenance confidence.

Security policycaution

The repository has no security policy, leaving vulnerability-reporting and response expectations unclear. This is a transparency gap, though dependency scanning provides some compensating project hygiene.

Workflow auditcaution

All 23 analyzed action references are unpinned, and the audit found a medium-confidence template-injection issue; however, there are no untrusted checkouts or dangerous workflow triggers, so this is workflow hygiene risk rather than a severe finding.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

No maintainer information available.

Direct Dependencies

DependencyLast ReleaseScore
twig/twig
Version ^3.0
—
—
react/http
Version ^0.8.0
—
—
psr/http-message
Version ^1.0
—
—
ringcentral/psr7
Version ^1.2.2
—
—

Weekly Downloads

Info

Last Published
6 years ago
Created
6 years ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform