The package is small and includes automated tests, while its stable version and declared GPL-3.0 license make its intended use clearer. The post-update hook adds operational risk, and the project offers limited security-process evidence.
42%
Total Score
50
67
The package has had only three releases, all clustered on November 7, 2021, with no release in nearly five years. That prolonged inactivity is a substantial maintenance and abandonment concern.
A post-update-cmd lifecycle script runs package-defined commands during dependency updates, adding operational risk beyond a package with no lifecycle hooks.
Automated tests are present, which supports basic project maturity, but the published artifact has no README for consumers and no changelog or release notes documenting this version.
The linked repository has zero stars and forks and only one watcher. Popularity is not decisive by itself, but it provides no supporting evidence of adoption for an already inactive project.
Composer build tooling is present, but no security scanning tools are reported, leaving a modest transparency and maintenance gap.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
guzzlehttp/guzzle Version ^7.4 | — | — |
symfony/dom-crawler Version ^5.3 | — | — |
symfony/css-selector Version ^5.3 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.