Risky to adopt for new projects: the latest release is about three years old and the maintainer says the project is being retired. It remains licensed, tested, linked to the matching repository, and not deprecated or archived, but ongoing maintenance cannot be expected.
43%
Total Score
25
64
75
The package includes a substantial README and tests, and the README explicitly says the project is being retired; the missing changelog is normal packaging practice and is not a concern here.
The package has had no releases in about three years: its latest release was September 3, 2023, with zero releases in the preceding 12 months of the assessment period. This is a substantial abandonment concern for a dependency.
The repository had zero commits and zero active maintainers during the last three months of the assessment period. Combined with the old latest release, this indicates that fixes and compatibility updates are unlikely.
Only one registry publishing account is listed. That is not inherently problematic for a user-owned project, but it leaves little visible publishing redundancy alongside the absence of recent activity.
The linked repository is not archived, but its last push was on September 3, 2023, consistent with the package’s stated retirement rather than active development.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
erusev/parsedown Version ^1.8.0@beta | — | — |
erusev/parsedown-extra Version ^0.8 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.