Usable with caveats: it is a small, clearly licensed package with a matching repository and no deprecation or install-time scripts. However, it has only two releases, no tests or documentation files, and no recorded commits in the last three months, so maintenance and transparency are limited.
62%
Total Score
75
100
75
75
The artifact and repository contain no README, tests, or changelog. For a six-file component this is a meaningful transparency and maintenance gap because there is no provided usage or regression evidence.
The package is 259 days old with only two releases and a median interval of about 259 days. This is limited maturity evidence, though the package is still relatively young.
There were zero commits and zero active maintainers in the last three months. This weakens evidence of ongoing maintenance, although the repository's recent push provides limited compensation.
Composer is used as a build tool, but no security scanning tool is configured. The missing scanning is a transparency gap, though it is not by itself evidence that the package is unsafe.
The repository has no security policy. For a small component this is a modest disclosure-process gap rather than a severe dependency risk.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
osynapsy/osynapsy-html2 Version 1.* | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.