This is a promising but still young package with strong basic transparency and packaging: it has an MIT license, README, changelog, tests in both the artifact and repository, a coherent 247-file source tree, no install-time lifecycle scripts, a matching repository, and recent release and commit activity. The main concerns are that version 0.2.1 is not a stable major release, the project is only 111 days old, all four commits in the last three months came from one contributor, and the repository lacks a security policy and explicit top-level GitHub Actions permissions. It appears reasonable to evaluate for use, but its maturity and bus-factor risks warrant monitoring and a fallback plan for important production dependencies.
78%
Total Score
50
79
80
The repository owner is an individual user rather than an organization, so the single-maintainer concentration is not visibly offset by organizational backing.
Five releases over 111 days, with a median interval of about 20 days and a release as recent as the collection date, show active early-stage development; the short history still limits evidence of long-term stability.
One contributor made 100% of the four recent commits, creating a genuine single-maintainer continuity risk; the repository is user-owned rather than organization-owned, so there is no shown organizational compensation.
There were four commits in the last three months and one active maintainer, indicating current activity but a relatively modest maintenance pace for assessing longer-term resilience.
Composer build tooling is present, but no security-scanning tools were detected, leaving a security-hygiene gap that is relevant to a dependency.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
tijsverkoyen/css-to-inline-styles Version ^2.2 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.