The package has a clear MIT license, a usable README, and no install-time scripts. Its single release and lack of repository activity leave it with a substantial abandonment risk for a dependency.
35%
Total Score
50
100
64
75
There has been only one release, published about 13 years ago, with no releases in the last 12 months. This is strong evidence that the package is no longer actively maintained.
The repository recorded zero commits and zero active maintainers in the last three months, consistent with a project that has been inactive for many years. This materially increases abandonment risk.
The repository has only 2 stars and 1 fork, so there is little visible community activity to provide support or maintenance capacity. Popularity is supporting evidence rather than the main concern.
Composer is used as a build tool, but no security scanning tools are present. The missing scanning is a modest transparency and maintenance gap, not severe on its own.
The repository has no security policy. For a package that parses input and produces HTML, this leaves vulnerability reporting expectations unclear, though it is secondary to the long inactivity.
We didn't find any vulnerabilities for this package.
No maintainer information available.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.