The package includes tests, a substantial README, an MIT license, and no install-time scripts. Organization backing and recent commits help, but workflow references are all unpinned and no security policy is present.
68%
Total Score
83
100
88
75
This is a young package, released 29 days ago with only one release, so long-term maintenance and release consistency are not yet demonstrated.
The repository received two commits in the last three months, showing some recent activity, but the volume is too small to establish a durable maintenance cadence.
Composer build tooling is present, but no security scanning tool was detected, leaving a modest transparency and maintenance gap.
The repository has no security policy, so vulnerability reporting and disclosure expectations are not documented.
The audit completed cleanly with no suspicious sinks or findings, but all seven action references are unpinned and one workflow grants top-level write permissions, creating workflow supply-chain and permission hygiene concerns.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
symfony/dom-crawler Version ^5.4 || ^6.4 || ^7.0 | — | — |
symfony/css-selector Version ^5.4 || ^6.4 || ^7.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.