The project has a long release history, a stable major version, clear licensing, and organization-backed ownership. Its repository lacks a security policy and security scanning, leaving transparency and maintenance safeguards weaker than its packaging suggests.
67%
Total Score
75
93
75
The repository recorded zero commits and zero active maintainers in the last three months, indicating a recent lull despite the latest package release.
The project uses Composer and Make, but no security-scanning tools were detected; this is a modest safeguard gap rather than evidence of abandonment.
The repository has no security policy, leaving users without documented vulnerability-reporting and response guidance.
Both workflows were analyzed successfully with no dangerous triggers, sinks, or audit findings, but both of the two action references are unpinned, weakening build reproducibility.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
psr/log Version ^1.0 || ^2.0 || ^3.0 | — | — |
psr/http-client Version ^1.0 | — | — |
psr/http-factory Version ^1.0 | — | — |
psr/http-message Version ^1.0 || ^2.0 | — | — |
symfony/dom-crawler Version ^6.4 || ^7.4 || ^8.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.