Usable with caveats: it has a long release history, a current stable release, and a maintained, well-documented repository. No commits were recorded in the last three months, and the repository lacks a security policy and explicit workflow token permissions.
74%
Total Score
67
100
80
The registry namespace and repository are owned by different personal accounts, both user-owned rather than organization-owned. This suggests a relatively narrow ownership base and provides less institutional continuity.
The repository recorded 0 commits and 0 active maintainers in the last three months. Although recent releases and merged pull requests provide some compensation, this still lowers confidence in sustained maintenance.
No SECURITY.md or equivalent security policy was found. This is a transparency gap for a library handling XML, certificates, and external resources, though it does not by itself indicate abandonment.
Both workflows lack top-level token permissions declarations. No workflow requests top-level write access, but explicit least-privilege permissions would provide stronger CI security hygiene.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
symfony/process Version ^5.4.47|^6.4.15|^7.1.8|^8.0 | — | — |
eclipxe/xmlschemavalidator Version ^3.0.5 | — | — |
eclipxe/xmlresourceretriever Version ^2.0.3 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.