It includes tests, a README, a matching MIT license, and release notes for this version. The repository is not archived, but it has no security policy and no recent issue or pull-request movement.
65%
Total Score
50
93
75
There were zero commits and zero active maintainers in the last three months. This is a meaningful recent-maintenance gap, although the repository was pushed in March 2026.
There were no new or closed issues and no merged pull requests in the last month, with 75 open issues and 17 open pull requests. That indicates limited recent project movement.
The repository uses Composer build tooling, which fits the package ecosystem. No security scanning tools were detected, a modest hygiene limitation rather than evidence of unsafe behavior.
The repository has no security policy. For a library with substantial downstream use, this weakens the transparency and reporting path, though it does not show a direct security defect.
The sole workflow was fully analyzed with no dangerous triggers, untrusted checkouts, injection findings, or write permissions. However, both of its two action references are unpinned, leaving avoidable workflow supply-chain exposure.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
erusev/parsedown Version ^2.0.0|^2.0.0-beta-1 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.