The MIT license, clear README, organization ownership, and security policy provide useful transparency. The project is only 49 days old, has one release, and has seen just two commits from one contributor, so long-term maintenance is not yet proven.
67%
Total Score
67
100
92
100
This is a young package, 49 days old, with only one release and no established release cadence. That limits evidence of maturity and ongoing maintenance.
All two recent commits came from one contributor, leaving maintenance dependent on a single active developer. Organization ownership provides some handoff capacity but does not remove the concentration concern.
Only two commits were recorded in the last three months, showing limited observed development activity for a package whose history is still short.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
league/commonmark Version ^2.7 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.