The README and MIT license make the package understandable and legally clear. It has no tests, security policy, or security scanning, leaving little assurance for a dependency that has not changed in over nine years. Use a maintained static-site generator instead.
8%
Total Score
0
42
50
Packagist marks the entire package as abandoned, with no replacement supplied. This is a direct warning against taking a new dependency on the package.
The latest release was published in June 2017, with no releases in the last 12 months; the package has had no release for over nine years, indicating abandonment risk.
The repository had zero commits and zero active maintainers in the last three months, consistent with the long-term abandonment indicators.
The linked repository is archived and was last pushed in June 2018, so it is no longer an active maintenance source.
Composer build tooling is present, but no security scanning tools are configured. This weakens maintenance assurance, though it is secondary to the archived and deprecated status.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
cocur/slugify Version ^2.5 | — | — |
league/plates Version ^3.3 | — | — |
rdlowrey/auryn Version ^1.4 | — | — |
symfony/console Version ^3.2 | — | — |
league/commonmark Version ^0.15.3 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.