Documentation, tests, and a matching source repository make its small scope understandable. The license mismatch deserves confirmation before adoption.
58%
Total Score
50
64
75
The package has only one release, published in August 2016, with no releases in the past 12 months. That long release gap creates a meaningful maintenance and abandonment concern.
There were no commits and no active maintainers in the past three months. This is the clearest current sign that maintenance may have stopped.
A GPL-2.0+ license is declared and a license file is present, but the artifact was detected as GPL-2.0. Confirm the intended licensing terms before use.
The repository uses Composer, but no security scanning tools were detected. This is a modest transparency and maintenance gap rather than a standalone adoption blocker.
The repository has no security policy. For a text-sanitization library, that leaves vulnerability reporting and response expectations undocumented.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
wikimedia/cdb Version ~1.0 | — | — |
wikimedia/textcat Version ~1.1 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.