The source tree is substantial, tested, licensed, and clearly matches the package, while organizational backing supports continuity. Its maintenance appears dormant, so future compatibility and issue response are uncertain.
60%
Total Score
75
100
88
83
The package has 11 releases but none in roughly seven years, with the latest published in April 2019. That long release gap is a meaningful maintenance concern despite the earlier regular cadence.
The repository recorded no commits and no active maintainers in the last three months, consistent with the long release gap. This materially increases abandonment and unaddressed-change risk.
The repository uses Make and Composer, showing basic build tooling, but it reports no security-scanning tools. The missing scanning is a minor hygiene gap rather than a decisive dependency risk.
The repository has no security policy, leaving vulnerability-reporting expectations unclear. This is a transparency gap, but the tested, licensed source and lack of install scripts partly limit its practical impact.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
ezyang/htmlpurifier Version ^4.0 | — | — |
michelf/php-markdown Version ^1.6 | — | — |
scrivo/highlight.php Version ^9.0 | — | — |
michelf/php-smartypants Version ^1.6 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.