It includes tests, a clear MIT license, and a matching source repository. No security policy or scanning is visible, so future maintenance and vulnerability response are uncertain.
62%
Total Score
50
83
75
The package has eight releases since July 2019, but none in the 12 months before collection; its latest release was about 16 months ago. This indicates materially slowed maintenance.
The repository recorded no commits and no active maintainers during the last three months. Together with the stale release cadence, this raises abandonment risk.
Composer build tooling is present, but no security scanning tools were detected. That leaves vulnerability detection less transparent.
The repository has no security policy, so there is no documented path for reporting vulnerabilities or understanding the project's response process.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
surda/cssmin Version ^1.0 | — | — |
tedivm/jshrink Version ~1.0 | — | — |
machy8/webloader Version ^2.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.