The package includes tests, clear usage documentation, a matching repository, and a minimal dependency profile. Its small user and contributor base, absent security policy, and no activity since September 2022 make long-term maintenance uncertain.
58%
Total Score
50
100
78
75
The repository is owned by an individual user rather than an organization, so the small maintainer base is not offset by visible organizational backing.
The package has only two releases, both published in September 2022, with no releases in the following four years. This indicates limited ongoing maintenance for a dependency consumers may need to keep compatible.
There were no commits or active maintainers in the last three months, consistent with the repository's last push in September 2022. This materially increases abandonment and compatibility risk.
The repository has three stars, no forks, and one watcher, indicating a very small adoption and review base. This is supporting evidence of limited external oversight rather than a severe risk by itself.
Composer is used for the build, but no security scanning tools are present. For this small PHP extension, that is a modest transparency and hygiene gap rather than evidence of unsafe code.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
league/commonmark Version ^2.3 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.