It has an Apache-2.0 license, tests, organization backing, and no install-time scripts. The package is too new to demonstrate sustained maintenance, and its missing README and security policy reduce transparency.
61%
Total Score
75
100
79
75
The artifact includes tests, and the repository also reports tests, which supports basic project quality. The package has no README, leaving consumers with less integration guidance.
This package was released once, 0 days ago, so it has no demonstrated release cadence or track record. That is a meaningful maturity concern, though its newness limits how strongly it indicates abandonment.
The repository has 0 commits and 0 active maintainers in the last 3 months. Because the package is only 0 days old, this is mainly missing maintenance evidence rather than proof of abandonment.
Composer is used as the build tool, which fits the package ecosystem, but no security scanning tool is present. The missing scanner is a hygiene gap rather than a severe dependency risk.
The repository has no security policy. That weakens vulnerability-reporting transparency, although the absence of a policy alone does not show that the package is unsafe.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
tijsverkoyen/css-to-inline-styles Version 2.4.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.