The package has a usable README, tests, stable versioning, organization backing, and no install-time scripts. Its last release and repository commit were about a year ago, while the declared proprietary license conflicts with the detected MIT license file.
61%
Total Score
75
100
81
83
The artifact contains an MIT license file, so it is licensed, but the manifest declares the package as proprietary; this mismatch reduces licensing transparency.
The package has 128 releases since June 2019, but no releases in the last 12 months; the long gap is a meaningful maintenance concern despite its substantial release history.
There were no commits and no active maintainers in the past three months, consistent with the year-long release gap and indicating inactive current development.
Composer is used for builds, but no security scanning tools are configured. This is a hygiene gap rather than evidence that the package is unsafe.
The repository has no security policy, leaving vulnerability reporting and response expectations undocumented.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
html2text/html2text Version >=4.2 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.