Clear licensing, a substantial README, and a small runtime dependency set make adoption easier. The active project has several contributors, but most recent commits come from one person and no security policy is published.
78%
Total Score
83
100
86
75
Six contributors were active, but the top contributor made 91.8% of the 1,555 recent commits. The organization backing helps provide continuity, yet the observed work remains highly concentrated.
Composer build tooling is present, supporting reproducible project workflows. No security-scanning tooling was detected, leaving a modest security-process gap.
The repository has no published security policy. This reduces transparency around vulnerability reporting and handling, though it is not evidence that the package is unsafe.
The current release is on the 0.x line, so its API may still change before a stable major release. It is not marked as a prerelease, and the recent release history shows active development.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
league/commonmark Version ^2.5 | — | — |
league/html-to-markdown Version ^5.1 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.