Its dependency set is modest, and the package has no install-time scripts. The small source tree and absent security policy leave little evidence of ongoing quality control; pin v1.0.4 only while evaluating an actively maintained alternative.
43%
Total Score
0
67
75
The package has made no release in over 1 year, despite four releases arriving within about 1 week in early 2025. That abrupt stop is a meaningful abandonment concern.
The repository recorded zero commits and zero active maintainers in the last 3 months, consistent with the release stoppage and providing no evidence of current maintenance.
The repository name does not match the package name, and no README package reference was found. A name mismatch can be normal for a sub-package, but the missing mention leaves package ownership less transparent.
The repository has 0 stars, 0 forks, and 1 watcher. Popularity is not required for a healthy small package, but these counters provide no supporting evidence of community use or review.
The linked repository has no security policy, reducing transparency for reporting and handling vulnerabilities. This is a hygiene gap rather than a standalone reason to reject the package.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
guzzlehttp/guzzle Version ^7.0.1 | — | — |
pipl/piplapis-php Version ^5.2 | — | — |
symfony/dom-crawler Version ^7.2 | — | — |
symfony/css-selector Version ^7.2 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.