The package has an Apache-2.0 license, tests, a matching organization-owned repository, and no install-time scripts. Composer is used for builds, but no repository security scanning or security policy is present.
65%
Total Score
75
100
88
83
The package is brand new: it has one release, published today, with no established release cadence. This limits evidence of maintenance and release reliability, though the absence of history is not proof of abandonment.
The repository has zero commits and zero active maintainers in the last three months. Because the repository was created today, this is primarily a lack of maintenance evidence rather than evidence of a collapsed project.
The repository uses Composer, showing a defined build tool, but reports no security scanning tools. The missing scanning is a modest transparency and hygiene gap.
No repository security policy was found. This weakens vulnerability-reporting transparency, although it is not by itself evidence that the package is unsafe.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
ezyang/htmlpurifier Version 4.19.1 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.