It has a long release history, stable versioning, and an organization-backed repository. Tests, licensing, and package-to-repository alignment support adoption, but the contributor and security picture is thin.
63%
Total Score
67
50
81
83
Eight runtime dependencies, including HTTP, parsing, logging, and related project libraries, create a meaningful dependency surface for this small plugin. The profile is understandable but adds maintenance exposure.
The package has existed for about 10 years with 20 releases, but it has had no releases in the past 12 months. This suggests slowing maintenance rather than abandonment on its own.
There were no commits and no active maintainers in the last three months. Combined with the lack of recent releases, this indicates a currently quiet project and raises abandonment risk.
There are no open issues and two open pull requests, but no issues or pull requests were merged in the last month. The absence of reported problems is positive, while the unmerged work suggests limited recent activity.
The repository has only 1 star, 1 fork, and 3 watchers. Popularity is supporting evidence rather than a verdict, but these numbers provide little community backup if maintenance stops.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
psr/log Version 1.* | — | — |
runopencode/sax Version ~3.0 | — | — |
guzzlehttp/guzzle Version ^6.3 | — | — |
symfony/dom-crawler Version ~2.8|~3.0 | — | — |
symfony/css-selector Version ~2.8|~3.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.