It has a clear MIT license, a readable usage guide, and only one runtime dependency. Its focused four-file codebase is simple, but the project provides little evidence of current maintenance or security oversight.
38%
Total Score
0
100
75
75
The package has had no release in nearly 11 years; all three releases were published within about one day in October 2015, leaving substantial abandonment risk.
The repository has recorded zero commits and zero active maintainers in the last three months, consistent with the long gap since its last update.
The repository has zero stars and forks and only one watcher. Popularity is supporting evidence rather than decisive, but it offers no additional maintenance signal here.
Composer is used for the build, but no security-scanning tool is configured, reducing evidence of ongoing dependency and code hygiene.
The repository has no security policy, so users have no documented reporting path; this is a transparency gap for a package that handles XML input.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.