Tests, a README, and a changelog improve the release’s transparency. Verify the licensing and repository identity before adopting it, especially because maintenance evidence is still limited.
53%
Total Score
50
71
67
The manifest declares GPL-3.0 while the artifact license file was detected as MIT. This unresolved mismatch creates a real legal and transparency concern despite the presence of license files.
A post-update-cmd lifecycle script runs package-managed code during dependency updates, adding a modest execution-surface concern that should be understood before adoption.
The repository is owned by an individual user rather than an organization, so there is no organizational backing to compensate for the single-contributor maintenance base.
The package was released today with only two releases, about 16 minutes apart, so there is not yet enough history to demonstrate durable maintenance.
All four recent commits came from one contributor, leaving maintenance dependent on a single person with no demonstrated handoff capacity.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
guzzlehttp/guzzle Version ^8.0 | — | — |
symfony/dom-crawler Version ^8.1 | — | — |
symfony/css-selector Version ^8.1 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.