A Parsedown Extra package for Laravel
70%
Total Score
caution
Usable with caveats: recent development has stalled and every workflow action is unpinned.
Only one account has registry publishing access. Because the repository is user-owned rather than organization-owned, this represents limited publishing depth and increases reliance on one maintainer.
The repository is owned by an individual user rather than an organization, so there is no demonstrated organizational backing to compensate for the single-maintainer structure.
The repository recorded zero commits and zero active maintainers in the last three months. The recent push and release history partly offset this, but current development activity is still a maintenance concern.
The repository has no security policy. This is a transparency and reporting gap, though it is not by itself evidence that the package is unsafe.
The workflow audit analyzed the single workflow completely and found no injection or dangerous-trigger issues, but all four action references are unpinned. The missing top-level permissions block is acceptable on its own; unpinned actions weaken build reproducibility and supply-chain hygiene.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
illuminate/config Version ^12.0.0 | — | — |
illuminate/support Version ^12.0.0 | — | — |
ezyang/htmlpurifier Version ^4.18.0 | — | — |
illuminate/filesystem Version ^12.0.0 | — | — |
erusev/parsedown-extra Version ^0.9.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.