The focused README, MIT license, and organization backing make the package straightforward to adopt. Its single recent release and all commits coming from one contributor leave limited evidence of long-term maintenance.
68%
Total Score
63
100
81
100
Only one registry account has publishing access, which is a narrow publishing base. The linked project is organization-owned, providing some backing for registry operations but not evidence of multiple active publishers.
This is a young package, 53 days old, with only one release and no established release cadence. That leaves limited evidence of sustained maintenance, though the release is recent rather than stale.
One contributor made 100% of the two commits in the last three months. Organization ownership provides some handoff capacity, but no second active contributor is shown.
The repository recorded two commits in the last three months, all from one active maintainer. Recent activity is present, but the small volume provides weak evidence of sustained maintenance.
The repository name matches the package name, so it does not appear to be piggy-backing on an unrelated project. The README does not mention the package name, a minor transparency gap despite the matching repository identity.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
league/commonmark Version ^2.7 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.