The clear README, MIT licensing, and small dependency set make the package straightforward to evaluate. Maintenance is concentrated in one contributor, with only one commit in the last three months, and the project has no security policy.
58%
Total Score
50
100
81
50
Eight releases in 176 days show active early development, but the very short history makes long-term maintenance less established. The median interval is about 1 hour 17 minutes, suggesting releases may be clustered rather than paced.
One contributor made 100% of the one commit in the last three months. With a user-owned project rather than organization backing, this creates a meaningful continuity risk.
Only one commit was recorded in the last three months, by one active maintainer. That is thin recent maintenance evidence for a young package.
Composer is used for builds, but no security-scanning tool was detected. The missing scan is a modest transparency and maintenance gap, not evidence of unsafe code.
The repository has no security policy. That leaves vulnerability reporting and response expectations unclear for a package intended to be integrated into projects.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
twig/twig Version ^3.10 | — | — |
symfony/yaml Version ^7.0 | — | — |
league/commonmark Version ^2.5 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.