The linked project has no security policy or automated security scanning, and its repository has only one star. The package includes a README, Composer build metadata, and three runtime dependencies, but its small project footprint offers little maintenance assurance.
38%
Total Score
25
100
50
75
The package has had only three releases, with none in the last 12 months; its latest release was over 11 years ago. This is strong evidence of abandonment for a web application dependency.
There were no commits or active maintainers in the last three months, consistent with the release history and indicating a serious maintenance gap.
The repository is not archived, but it was last pushed over 10 years ago. The non-archived status does not compensate for the prolonged inactivity.
The manifest declares a proprietary license, so the release is licensed, and the repository also contains a license file. However, the proprietary terms may restrict use in projects expecting open-source licensing.
The package includes a short README, while the absence of tests and a changelog is normal for published artifacts and is not treated as a gap here. The README provides only limited consumer guidance.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
twig/twig Version 1.9.0 | — | — |
mustangostang/spyc Version 0.5.1 | — | — |
ezyang/htmlpurifier Version 4.6.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.