Package Health

getpop/dom-crawler

This is a healthy, actively maintained release with a strong release cadence, stable versioning, current repository activity, clear licensing, source/artifact alignment, tests, and no deprecation or install-time lifecycle scripts. The main concerns are that all recent repository commits come from one contributor, the repository has minimal external adoption, and no security scanning or security policy was observed; organizational ownership provides some maintenance backing but does not eliminate the single-contributor risk. Overall, it appears reasonable to depend on, with normal supply-chain due diligence recommended.

Latest 19.2.4PackagistPackagist

78%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

70

Dependencies
Dependencies
Evaluates the health and security of package dependencies

100

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

89

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

90

Health Score Breakdown

Maintainerscaution

Only one registry publishing account is listed, which is a limited publishing redundancy; the linked repository is organization-owned and the package has substantial recent release activity, partly compensating for this administrative concentration.

Repo bus factorcaution

All 14 recent commits came from one contributor, creating a genuine continuity risk. Organization ownership provides some ability to hand off maintenance, but no second active contributor is shown.

Repo issue activitycaution

There were no new or closed issues or pull requests in the last month, and open issue count is unknown; this provides little evidence of community support, though the active release and commit signals compensate for part of the gap.

Repo popularitycaution

The repository has only 1 star and 0 forks, so external adoption and independent validation appear limited; popularity is supporting evidence, so this warrants caution rather than a severe penalty.

Repo toolingcaution

Composer build tooling is present, but no security scanning tools were detected; the missing scanning reduces assurance about ongoing repository hygiene.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

Leonardo Losoviz

Direct Dependencies

DependencyLast ReleaseScore
masterminds/html5
Version ^2.7
—
—
symfony/dom-crawler
Version ^6.0
—
—
symfony/css-selector
Version ^6.0
—
—
getpop/component-model
Version ^19.2.4
—
—

Weekly Downloads

Info

Last Published
19 days ago
Created
3 years ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform