The project has no tests or security policy, and its workflow uses five unpinned actions. A matching repository, MIT license, build tooling, and release notes provide useful transparency for this small command-line package.
61%
Total Score
50
75
50
The package has only four releases and none in the last 12 months; its latest release was about 2 years and 9 months ago, indicating meaningful maintenance risk.
The repository recorded no commits and no active maintainers in the last 3 months, reinforcing the evidence of stalled maintenance rather than merely a slow release cadence.
Composer and Box provide an explicit build path, which supports reproducible package construction, but no security scanning tooling is configured.
No security policy is present. This is a modest transparency gap for a package that handles downloaded content, though it is not evidence of a security defect by itself.
The single workflow was fully analyzed with no dangerous triggers, sinks, or audit findings, but all five action references are unpinned, leaving avoidable build-integrity exposure.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
symfony/console Version ^5.3 | — | — |
guzzlehttp/guzzle Version ^7.3 | — | — |
symfony/dom-crawler Version ^5.3 | — | — |
symfony/css-selector Version ^5.3 | — | — |
league/html-to-markdown Version ^5.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.