The package includes tests, a README, and no install-time scripts, but its license declaration conflicts with the detected license file. Its small repository has no security scanning or policy, adding little support for continued maintenance.
12%
Total Score
0
43
83
Packagist marks the entire package as abandoned, with no replacement provided; this is a severe adoption risk for a dependency.
The package has had no releases in roughly nine years, with zero releases in the last 12 months; this strongly indicates abandonment.
The repository recorded zero commits and zero active maintainers in the last three months, consistent with its long-standing lack of maintenance.
The linked repository is archived and was last pushed in October 2016, so active maintenance and future fixes cannot be expected.
The artifact contains a license file and the repository also has one, but the declared MIT license conflicts with the detected BSD-3-Clause text; the mismatch reduces transparency.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
guzzlehttp/guzzle Version ~6.2 | — | — |
symfony/dom-crawler Version >=2.6 | — | — |
symfony/css-selector Version >=2.6 | — | — |
gabrielelana/byte-units Version ^0.3.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.