The package has clear documentation, tests, regular releases, and an active repository. Its license files conflict with the MIT declaration, while recent work comes from one contributor and no security policy is published. Pin this version and verify the intended license before adoption.
68%
Total Score
50
93
50
The manifest declares MIT and the package includes license files, but the detected artifact license is BSD-3-Clause, creating a material licensing mismatch that should be resolved before use.
The package defines a post-create-project-cmd script, which adds install-time behavior and modest supply-chain exposure compared with a package without lifecycle scripts.
All recent commits came from one contributor, with a 100% share. The repository owner is an individual rather than an organization, so there is no provided backing signal to compensate for this concentration.
Only 2 commits were recorded in the last 3 months, indicating limited recent development activity despite the recent release.
The repository has no published security policy. This reduces transparency for reporting and handling vulnerabilities, although it does not by itself indicate abandonment.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
ezyang/htmlpurifier Version ^4.17 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.