The source tree is very small and provides no security scanning, while the repository has no recorded issue or pull-request activity. It is not archived and uses a stable release with ordinary Composer dependencies, but these positives do not offset the transparency gaps.
38%
Total Score
50
100
61
67
The package has only 2 releases, both dating from August 2021, with no release in more than 5 years. This is strong evidence of abandonment risk for a dependency.
Neither the package nor the linked repository declares or includes a recognized license. That creates a real adoption and redistribution risk.
The package contains only 10 files, including a very small source tree and Composer metadata. This may fit a small educational utility, but provides limited evidence of mature project practices.
The artifact has no README, which weakens consumer transparency for a library. Missing tests and changelog are normal packaging practice and do not add concern here.
There are no open issues or pull requests and no activity in the past month. Combined with the old last push, this supports concern about ongoing maintenance.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
guzzlehttp/guzzle Version ^6.3 | — | — |
symfony/dom-crawler Version ^4.2 | — | — |
symfony/css-selector Version ^5.3 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.