The package is clearly licensed, small, and free of install-time scripts, with organizational ownership behind the repository. Its registry release is nearly nine years old, recent commit activity is absent, and the linked repository does not identify this package; verify the source before adopting it.
44%
Total Score
75
100
81
83
Only three releases exist, with the latest published in September 2017 and none in the last 12 months. This leaves the registry release substantially stale despite the repository being updated later.
There were no commits and no active maintainers in the three months measured. The recent repository push is reassuring, but it does not demonstrate sustained current maintenance.
The repository name does not match the package name and its README does not mention the package. Although a subpackage can legitimately use a different repository name, this makes package ownership and provenance harder to verify.
Composer is used for builds, showing ecosystem-appropriate tooling, but no security scanning tool is configured, leaving a modest transparency and maintenance gap.
The repository has no security policy. For a small extension this is a minor transparency gap, but it provides no documented path for reporting security issues.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
mediawiki/textextracts Version ~1.26 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.