The package has a small, clearly scoped dependency set and no install-time scripts. Its documentation and licensing are thin, while the source project shows no recent maintenance, making long-term ownership a risk.
38%
Total Score
0
50
75
Only one release exists, published about five years ago, with no releases in the last 12 months. The absence of deprecation is reassuring but does not offset the lack of release history.
The repository recorded no commits and no active maintainers in the last three months, consistent with the last push being about five years ago. The repository is not archived, but there is still no evidence of active maintenance.
No declared license or license file was found in the package or repository, leaving the legal terms for reuse unclear.
The artifact has no README, which matters for a package consumers must integrate, while missing tests and a changelog in the published artifact are normal packaging practice. No repository documentation or test evidence compensates for the missing consumer documentation.
Composer is used for the build, but no security-scanning tool is configured. This is a modest transparency and maintenance gap rather than evidence that the package is unsafe.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
guzzlehttp/guzzle Version ^7.3 | — | — |
symfony/dom-crawler Version ^5.3 | — | — |
symfony/css-selector Version ^5.3 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.