The MIT license, usable README, and modest dependency set reduce adoption friction. Open pull requests and absent security tooling leave little evidence of active stewardship.
42%
Total Score
50
79
75
The latest release was published in February 2016, more than 10 years ago, with no releases in the last 12 months. This is strong evidence that the package is no longer actively maintained.
The repository recorded zero commits and zero active maintainers in the last 3 months, consistent with the long release gap. The repository is not archived, but recent maintenance capacity is not evident.
There are 9 open pull requests, with no new or merged pull requests in the last month. This suggests unresolved maintenance work rather than an actively responsive project.
Composer is used for builds, which is appropriate, but no security scanning tools are configured. That is a transparency and maintenance gap, though not severe by itself.
The repository has no security policy, leaving no stated process for reporting or handling vulnerabilities. This modestly reduces transparency for a dependency project.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
symfony/yaml Version ~2.6 | — | — |
league/plates Version 3.* | — | — |
symfony/console Version ~2.6 | — | — |
erusev/parsedown Version ^1.6 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.