Usable with caveats: the package is licensed, documented, tested, and not deprecated or archived. However, its last release was about 7 years ago and the repository has had no recent commit activity, which raises maintenance concerns for an HTML-filtering library.
58%
Total Score
75
100
81
88
The latest registry release was in March 2019, about 7 years ago, and there were no releases in the last 12 months. This is a meaningful maintenance concern for a library handling user-supplied HTML.
The repository recorded zero commits and zero active maintainers in the last 3 months, reinforcing the concern that development has effectively stalled.
Composer build tooling is present, but no security scanning tools were detected. For a package intended to filter HTML and help prevent XSS, the absence of visible security scanning is a transparency gap.
The linked repository is not archived, but it was last pushed about 4 years ago. The non-archived status is reassuring, while the age of the last push limits evidence of ongoing maintenance.
The repository has no security policy. That is a maintenance and vulnerability-response gap for a security-relevant HTML filtering library, though it is not evidence that the package is malicious.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.