It has a clear MIT license, a usable README, and a repository that matches the package. The single release and no repository commits in over six years leave its maintenance uncertain, so adopting it carries meaningful abandonment risk.
42%
Total Score
50
50
78
75
This package has only one release, published over six years ago, with no releases in the last 12 months. That is strong evidence of limited ongoing maintenance.
The repository recorded zero commits and zero active maintainers in the last three months, and its last push was over six years ago. This substantially increases abandonment risk.
The package declares 12 runtime dependencies and no development dependencies. This creates a relatively broad maintenance surface, though the signal alone does not show unresolved or unsafe dependencies.
The repository has one star and no forks, indicating very limited visible adoption. Popularity is only supporting evidence, but it offers little compensating confidence for the stale maintenance record.
Composer is used as the build tool, which is appropriate for this PHP package. No repository security scanning is configured, leaving a modest transparency and maintenance gap.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
soma/soma Version ^1.0 | — | — |
erusev/parsedown Version ^1.7 | — | — |
intervention/image Version ^2.5 | — | — |
maiorano84/shortcodes Version ^1.2 | — | — |
erusev/parsedown-extra Version ^0.7.1 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.