The package includes tests, a usable README, and no install-time scripts, but has only one registry maintainer and no security scanning. Its small repository footprint limits confidence in long-term compatibility.
38%
Total Score
33
100
72
88
The latest release was in July 2015, with no releases in the last 12 months and only three releases overall. This long period without published updates is strong evidence of abandonment risk.
The repository recorded no commits and no active maintainers in the last three months. Combined with the last push being in 2017, this indicates prolonged maintenance inactivity.
No license is declared, and neither the package artifact nor the linked repository contains a license file. This creates a material adoption and redistribution concern.
Only one registry account has publish access. This is a thin publishing base and increases continuity risk, especially alongside the lack of recent release activity.
The registry namespace and repository owner are different user accounts, with the repository owned by an individual rather than an organization. This gives limited evidence of institutional backing.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
twig/twig Version * | — | — |
michelf/php-markdown Version * | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.