The package is documented, licensed, and has repository tests, which helps integration. Its maintenance and security visibility are weak, so pinning this release leaves little expectation of fixes.
44%
Total Score
50
100
81
83
Only two releases exist, and none were published in the last 12 months; the latest release is about five years old. This is strong evidence of a possibly abandoned package.
The repository recorded zero commits and zero active maintainers in the last three months, consistent with the long release gap and leaving little evidence of ongoing maintenance.
There were no new or closed issues or pull requests in the last month, while four issues remain open. This provides no recent sign of issue handling.
Composer build tooling is present, but no security-scanning tools were detected. This is a modest transparency and maintenance weakness, not evidence of unsafe behavior by itself.
The repository has no security policy, reducing transparency about vulnerability reporting and response for a package that processes application text.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.