The source repository remains active in pull requests, and this release has clear notes, a license, and repository tests. Commit activity has been absent for three months, while both workflows grant broad write access and no security policy is published.
68%
Total Score
75
93
50
The package defines post-install and post-update Composer scripts. These scripts add installation-time behavior and warrant review, but their presence alone is not evidence of poor package health.
The package has only three releases and none in the last 12 months; the latest release was about two years ago. This is a meaningful maintenance concern, although recent repository activity partly offsets abandonment risk.
The repository recorded no commits and no active maintainers in the last three months. Recent pull requests show some activity, but the lack of commits still weakens evidence of ongoing maintenance.
No security policy is published in the repository. This is a transparency gap for a package handling HTTP middleware, though it is not by itself a severe dependency risk.
Both analyzed workflows use top-level write permissions, broader than necessary, but the audit found no untrusted checkout, script injection, unpinned action, or other reported workflow issue.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
react/promise Version ^3 | — | — |
psr/http-message Version ^1.1 | — | — |
thecodingmachine/safe Version ^2.5 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.