The release has a GPL-3.0 declaration, tests, and a readable package layout, which provide basic consumer support. It lacks a security policy and runs a post-update command, adding modest operational risk.
42%
Total Score
0
70
50
The package is over five years old, has only 5 releases, and has had no releases in the last 12 months. This strongly indicates abandonment risk for a dependency.
The repository recorded 0 commits and 0 active maintainers in the last 3 months, consistent with the release history showing no updates since December 2020.
A post-update-cmd lifecycle script runs during dependency updates, creating an additional execution surface that consumers should understand before adoption.
The repository name does not match the package name and its README does not mention the package, so the source-package relationship is unclear and weakens transparency.
The linked repository has no security policy. For a package that fetches external course data, this leaves vulnerability-reporting expectations undocumented.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
guzzlehttp/guzzle Version ^7.2 | — | — |
symfony/dom-crawler Version ^5.2 | — | — |
symfony/css-selector Version ^5.2 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.