The repository is maintained by an organization, is not archived, includes tests and a useful README, and has a small dependency footprint. Recent commit activity is absent, and the license text says GPL-3.0 while the manifest declares GPL-2.0-or-later.
65%
Total Score
75
100
79
83
A license file is present, but it was detected as GPL-3.0 while the manifest declares GPL-2.0-or-later. This mismatch needs clarification before adoption where license compatibility matters.
There were no commits and no active maintainers in the last 3 months. This is a meaningful maintenance concern, although the recent push and release history provide some counterevidence.
Composer build tooling is present, but no security-scanning tools were detected. The missing scanning layer is a modest transparency and hygiene gap, not evidence of unsafe code.
The repository has no security policy. For a small extension this is a limited gap, but it reduces clarity about how security issues are reported.
The assessed version is a prerelease, and 5 of the 9 recent releases were prereleases. Consumers should expect more change than with a final stable release.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
league/commonmark Version ^2.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.