Usable with caveats. The package is actively released, clearly documented, tested in its repository, and backed by the matching organization, but no commits or issue activity were recorded in the last three months and the workflow lacks explicit token permissions and security scanning.
74%
Total Score
67
100
94
88
No commits and no active maintainers were recorded during the last three months. The recent release partly offsets this, but the lack of current repository activity is a meaningful maintenance concern.
There were no new or closed issues or pull requests in the last month, despite 3 open issues and 3 open pull requests; this provides limited evidence of ongoing issue handling.
Composer build tooling is present, but no security scanning tools were detected. For a package focused on XSS protection, that is a transparency and maintenance gap, though it is not by itself evidence of unsafe code.
The only workflow has no top-level token permissions declaration. Although no write permissions were observed, explicit least-privilege settings would provide stronger workflow security transparency.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
voku/anti-xss Version ~4.1.42 | — | — |
voku/portable-ascii Version ~2.0.0 | — | — |
illuminate/contracts Version ^10.48|^11.44|^12.40|^13.0 | — | — |
spatie/laravel-package-tools Version ^1.9.2 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.