The package is clearly licensed, documented, and backed by a matching organization repository with tests. The lack of recent releases or commits makes future fixes uncertain, while the release notes warn that the API is incomplete and changing.
58%
Total Score
67
79
50
The package has 43 releases over more than nine years, but none in the last 12 months; the latest release was about 16 months before collection, which weakens confidence in ongoing maintenance.
There were no commits and no active maintainers in the last three months, a meaningful sign that fixes and development may currently be stalled.
Only three issues are open, but there were no new or closed issues and no pull requests in the last month; this supports the broader picture of limited recent activity.
The repository uses Composer and Phing, but no security scanning tools were detected. That is a modest transparency and maintenance gap rather than evidence of an unsafe release.
No repository security policy was found, leaving vulnerability-reporting expectations undocumented for a library that handles HTML and form-related functionality.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
theseer/css2xpath Version ^2.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.