Package Health

spiral/stempler

Stempler, HTML markup processor and template engine framework

Latest 3.17.2PackagistPackagist

76%

Total Score

healthy

Healthy, with strong release continuity and organization backing offsetting a concentrated contributor base.

Are you affected? Scan for Free

Health Score Breakdown

Repo bus factorcaution

All 9 commits in the last three months came from one contributor, creating a concentrated maintenance risk. The organization-owned repository provides some ability to hand maintenance off, so this is a caution rather than a severe risk.

Security policycaution

No security policy was found in the repository, which is a transparency gap for reporting vulnerabilities, but it is not evidence of abandonment by itself.

Workflow auditcaution

Both workflows were analyzed with no dangerous audit findings, unsafe checkout, or script injection. However, both action references are unpinned, leaving a modest reproducibility and action-integrity gap; missing top-level permissions blocks are not concerning here because neither workflow requests top-level write access.

Vulnerabilities

TitleVersionsSeverity
AIKIDO-2026-28946
spiral/stempler is vulnerable to Cross-Site Scripting (XSS) in versions 2.7.0 - 3.17.1.
2.7.0 - 3.17.1
Medium

Package versions

Maintainers

Anton Titov (wolfy-j)
Pavel Butchnev (butschster)
Aleksei Gagarin (roxblnfk)
Maksim Smakouz (msmakouz)

Direct Dependencies

DependencyLast ReleaseScore
spiral/core
Version ^3.17.2
—
—
myclabs/deep-copy
Version ^1.9
—
—

Weekly Downloads

Info

Last Published
2 months ago
Created
9 years ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform