The single-person project has no security policy and no recent repository activity, leaving little evidence of ongoing maintenance. Clear documentation, licensing, and a matching source repository reduce transparency concerns.
45%
Total Score
25
79
75
The package has had no release in over 3 years and none in the last 12 months, with only 3 releases overall; this is substantial abandonment risk.
The repository recorded 0 commits and 0 active maintainers in the last 3 months, reinforcing that maintenance has stopped rather than merely slowed.
Only one registry account has publish access. That is a thin publishing base, and no organization backing is shown to compensate for the concentration.
The repository has 0 stars, 0 forks, and 1 watcher. Popularity is only supporting evidence, but these figures provide no community signal to offset the inactivity.
The repository has no security policy, reducing transparency for reporting and handling vulnerabilities in a package with runtime dependencies.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
erusev/parsedown Version ^1.7.4 | — | — |
composer/installers Version ^1.9 | — | — |
erusev/parsedown-extra Version ^0.8.1 | — | — |
raffaelj/parsedown-tasks Version ^0.1.0 | — | — |
benjaminhoegh/parsedown-toc Version ^1.4.3 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.