Clear licensing, a substantial README, and release notes help consumers. The repository is not archived, but it lacks a published security policy.
58%
Total Score
50
90
50
The latest registry release was published in September 2018, with no releases in the last 12 months. This is a significant freshness concern for a dependency, despite the package having an established release history.
The repository recorded zero commits and zero active maintainers in the last three months, indicating no current development activity. A push in April 2024 shows the repository is not entirely abandoned, but does not offset the stale published release.
The linked repository has no security policy, leaving vulnerability-reporting expectations unclear. This is a transparency gap, though it is less severe than an archived repository or withdrawn release.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
michelf/php-markdown Version ~1.8 | — | — |
michelf/php-smartypants Version ~1.8 | — | — |
kartik-v/yii2-krajee-base Version >=1.9 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.