The package includes tests and a small, understandable source tree, but its publishing and maintenance evidence is thin. The post-update script and missing license add adoption risk for a package that has not changed since 2020.
38%
Total Score
67
50
No declared license, license file, or repository license file was detected. Without licensing terms, downstream use and redistribution are unclear.
The package declares a post-update-cmd lifecycle script, so dependency updates can execute package-defined commands. This adds supply-chain and maintenance risk even though no malicious behavior is established here.
Only one release exists, published nearly six years ago, with no releases in the last 12 months. That is strong evidence of abandonment risk for a dependency.
The repository has zero stars and forks and only one watcher. Popularity is not required for a healthy small package, but these counters provide no supporting evidence of active community use.
The repository is not archived, which is a compensating sign. However, its last push was nearly six years ago, consistent with the stale release history.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
guzzlehttp/guzzle Version ^7.2 | — | — |
symfony/dom-crawler Version ^5.2 | — | — |
symfony/css-selector Version ^5.2 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.