Usable with caveats: the repository is active and organization-backed, with a clear README and no install-time scripts. However, the latest registry release was over five years ago and recent work is limited to one contributor, while no security policy is provided.
62%
Total Score
67
100
79
75
The package has five releases but none in the last 12 months, and its latest registry release was published in January 2021. This is a meaningful maintenance concern despite the earlier release cadence being reasonably regular.
All three recent commits came from one contributor, creating concentration risk. Organization ownership provides some capacity for handoff, but no second active contributor is shown.
Three commits were recorded in the last three months, showing some current activity, but all came from one active maintainer and do not yet demonstrate a broad maintenance base.
Composer is used as a build tool, providing basic project tooling, but no security-scanning tools were detected, leaving security-process transparency limited.
The repository has no security policy, so users lack documented guidance for reporting and handling vulnerabilities.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
league/commonmark Version ^1.5.3 | — | — |
composer/installers Version ^1.9 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.