The release includes tests and a declared GPL-3.0 license, but its history is only two releases on one day and the README is minimal. No repository security scanning or security policy is present.
55%
Total Score
100
69
50
The linked repository name does not match the package name, and its README does not mention the package. That weakens confidence that the repository is the package's actual source, despite the repository being available.
Tests are present in both the package and repository, which is a positive sign, but the README is only 21 characters long and offers little consumer guidance. The missing changelog is normal packaging practice and is not a concern.
The package is only 111 days old and has two releases, both published on the same day with a median interval of about 24 minutes. This provides little evidence of sustained maintenance.
Composer is used for the build, but no security scanning tools are configured. This leaves the project with limited visible safeguards for dependency and build health.
The repository has no security policy. For a small, young package this is a transparency gap, although it is not severe enough to make the release unfit on its own.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
guzzlehttp/guzzle Version ^7.10 | — | — |
symfony/dom-crawler Version ^8.0 | — | — |
symfony/css-selector Version ^8.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.