Risky to adopt: the package has seen no release in nearly three years and only two releases, while its documentation is too sparse to support confident integration. It is not deprecated and declares a license, but maintenance and project transparency remain weak.
42%
Total Score
50
100
70
50
Only two releases were published, both on the same day, and there has been no release in nearly three years. This is strong evidence of an inactive or unfinished project.
The package defines a post-update-cmd lifecycle script, which adds install or update behavior that deserves review before adoption. No provided evidence shows that the script is necessary or harmless.
The registry lists only one maintainer account, leaving little visible redundancy if that person stops maintaining the package. This is a meaningful resilience concern, though access records do not prove current activity.
A README is present, but it contains only 56 characters and does not meaningfully explain how to use the component; the absence of packaged tests and a changelog is normal for a published artifact.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
guzzlehttp/guzzle Version ^7.8 | — | — |
symfony/dom-crawler Version ^4.2 | — | — |
symfony/css-selector Version ^6.3 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.