The BSD-3-Clause licensing, tests, README, and small dependency set make adoption straightforward. Workflow checks are complete but use unpinned actions, and no security policy or scanning is present.
62%
Total Score
50
100
88
50
Only one registry maintainer is listed, so publishing capacity appears concentrated in a single person. This is a modest resilience concern for a user-owned project.
The package has six releases since November 2014, but none in the last five years; the latest release was in July 2021. This materially raises abandonment risk.
There were no commits and no active maintainers in the last three months, consistent with a project whose maintenance has largely stopped.
Composer build tooling is present, but no security-scanning tools were detected. For a small parser this is a hygiene gap rather than a severe risk.
The repository has no security policy. That reduces transparency for reporting and handling vulnerabilities, though it does not by itself show that the package is unsafe.
| Title | Versions | Severity |
|---|---|---|
CVE-2015-10029 kelvinmo/simplexrd is vulnerable to Improper Restriction of XML External Entity Reference in versions 0.0.0 - 3.1.1. | 0.0.0 - 3.1.1 | Critical |
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.