Library to abstract html manipulation
70%
Total Score
caution
Usable with caveats: recent releases are offset by one-contributor maintenance and workflow credential and pinning concerns.
All 4 recent commits came from one contributor, so maintenance is concentrated. Organization backing provides some handoff capacity, but no second recent contributor is shown.
Composer build tooling is present, but no security scanning tool was detected. The missing scanning is a modest transparency and maintenance gap rather than evidence of abandonment.
The repository has no security policy. For a library that processes HTML, this leaves vulnerability-reporting guidance unclear.
All 6 analyzed action references are unpinned, and high-confidence secrets-inherit findings affect the CI and release workflows. There are no untrusted checkouts or script-injection findings, limiting the severity.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
innmind/url Version ~5.0 | — | — |
innmind/xml Version ~9.0 | — | — |
innmind/immutable Version ~6.0 | — | — |
innmind/filesystem Version ~9.0 | — | — |
innmind/validation Version ~3.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.