The package includes tests, a useful README, and release notes, while its organization backing provides some continuity. Its dependency and workflow setup are otherwise ordinary, but legal and maintenance safeguards remain incomplete.
58%
Total Score
50
100
71
50
The manifest says “TODO,” with no detected license and no license file in the package or repository. That leaves the legal terms for using this dependency unclear.
All five releases were published on the same observed day, so this package has not yet demonstrated a sustained release record. That is a maturity concern, though the release history is very recent rather than clearly abandoned.
All recent commit activity comes from one contributor, creating concentration risk. The organization-owned repository provides some ability to hand off maintenance, so this is a caution rather than a severe risk.
Only one commit was recorded in the last three months, from one active maintainer. That indicates limited recent maintenance capacity.
The project uses Composer, but no security-scanning tool was detected. This is a modest transparency and maintenance gap, not evidence of a defect.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
mautic/core-lib Version ^4.0|^5.0 | — | — |
symfony/dom-crawler Version ~4.4.0|~5.4.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.