Tests, a README, and a matching repository make the code easier to inspect. Treat compatibility and future fixes as uncertain because the project shows little evidence of ongoing ownership.
43%
Total Score
50
100
67
75
The latest release was published nearly five years ago, and there have been no releases in the last 12 months. Fifteen total releases show some past activity, but not current maintenance.
There were no commits and no active maintainers in the last three months, consistent with the repository having been inactive for nearly five years. This materially increases abandonment and compatibility risk.
The repository name matches the package name, supporting that it is the intended source. The README does not mention the package name, a minor transparency gap despite the name match.
The repository has zero stars, forks, and watchers. Popularity is supporting evidence rather than a verdict, but this offers no additional evidence of community support.
Composer is used for the build, but no security scanning tools are configured. The build setup is appropriate, while the missing scanning is a modest transparency gap.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
league/commonmark Version ^1.1.0 | — | — |
spatie/commonmark-highlighter Version ^2.1 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.