The package includes a README, changelog, license, and stable non-prerelease version. Its 21 runtime dependencies and post-update script add integration and update complexity; the repository could not be found, limiting verification.
61%
Total Score
50
50
90
75
The package declares 21 runtime dependencies and no development dependencies, creating a broad runtime trust and compatibility surface for a static-site tool.
A post-update-cmd lifecycle script runs during Composer updates, adding some supply-chain and upgrade complexity even though this is not inherently unsafe.
Only one registry account has publish access, leaving the release process dependent on a single maintainer and creating a modest continuity risk.
The package has existed for about 2 years and 7 months with 64 releases, but only 3 releases occurred in the last 12 months, indicating a relatively slow recent cadence.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
psr/log Version 2.0.0 | — | — |
league/plates Version ^3.5 | — | — |
monolog/monolog Version ^2.9.3 | — | — |
scssphp/scssphp Version ^v2.1.0 | — | — |
league/container Version ^4.2 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.