It includes tests, a README, a stable v1 release, and a small dependency set. Its single publisher and absent security scanning leave limited independent assurance. Pin this version until the source-package relationship is clarified.
62%
Total Score
100
100
78
67
The linked repository name does not match the package, and its README does not mention the package, so ownership of the published artifact is unclear.
A post-update Composer script executes package-defined behavior during dependency updates, adding a modest supply-chain and reproducibility consideration.
There were three releases, all clustered within about two days, followed by roughly five months without another release; this gives limited evidence of sustained maintenance.
Composer build tooling is present, but no security-scanning tooling was detected, which limits automated assurance without making the package unfit by itself.
No repository security policy was found, leaving vulnerability reporting and response expectations undocumented; this is a transparency gap for a small project.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
guzzlehttp/guzzle Version ^7.10 | — | — |
symfony/dom-crawler Version ^7.4 | — | — |
symfony/css-selector Version ^7.4 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.