The package is clearly documented and includes repository tests, while its workflow has no audit findings and uses read-only permissions. It is still too new to demonstrate sustained maintenance, and its two workflow actions are unpinned.
68%
Total Score
50
86
50
The package is less than one day old with only two releases, so there is not yet enough history to establish mature release practices. This may reflect a newly launched project rather than abandonment.
The repository records zero commits and zero active maintainers over the last three months, leaving sustained maintenance unproven. Because the package is less than one day old, this is an evidence gap more than clear abandonment.
Composer build tooling is present, but no security scanning tool was detected. For a newly published library this is a modest supply-chain hygiene gap, not a severe risk.
The repository has no security policy, reducing transparency for reporting vulnerabilities. The small, newly created project provides limited context that would otherwise compensate for this gap.
The one workflow was fully analyzed with no audit findings, no untrusted checkouts or script injection, and read-only permissions; however, both of its two action references are unpinned, leaving avoidable update risk.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
phpunit/phpunit Version ^12.5|^13.2 | — | — |
symfony/dom-crawler Version ^7.4|^8.1 | — | — |
symfony/css-selector Version ^7.4|^8.1 | — | — |
symfony/polyfill-php84 Version ^1.33 | — | — |
symfony/polyfill-php85 Version ^1.33 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.