The repository is intact, licensed, and backed by tests and a clear README. Recent commits are absent, and all six workflow actions are unpinned.
58%
Total Score
50
100
81
50
The package has had no registry releases since January 2022, despite 12 releases overall; this is a substantial maintenance concern for a dependency.
There were zero commits and zero active maintainers in the last three months, indicating little current maintenance capacity and reinforcing the stale release history.
Composer build tooling is present, but no security-scanning tools were detected; this is a modest transparency and hygiene gap rather than evidence of abandonment by itself.
The repository has no security policy, leaving vulnerability-reporting expectations unclear; this is a minor transparency gap for a small development-only package.
Both workflows were analyzed cleanly with no dangerous triggers, untrusted checkouts, or audit findings, but all six action references are unpinned, leaving avoidable workflow supply-chain exposure.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
symfony/dom-crawler Version ^5.1.8|^6.0 | — | — |
symfony/css-selector Version ^5.1|^6.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.