Release activity has stopped for over two years, with no commits in the past three months. The repository is identifiable, tested, licensed, and not archived, but it lacks a security policy and uses four unpinned workflow actions.
62%
Total Score
75
100
88
67
The package has made seven releases since 2016, but none in the last two years and three months. This weakens confidence in ongoing maintenance for a security-focused library.
There were no commits and no active maintainers in the past three months. This is a meaningful maintenance warning, although the repository was pushed more recently than the latest package release.
The project uses Composer, but no security scanning tools were detected. For an HTML sanitization library, that is a modest transparency and maintenance gap.
The repository has no security policy. That makes vulnerability reporting and response expectations less clear for a security-sensitive package.
The single workflow was fully analyzed with no dangerous triggers, sinks, or audit findings, but all four action references are unpinned. The workflow also lacks a top-level permissions block, which is acceptable on its own.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.