The package includes tests, a README, and release notes for this version, with organizational backing and no install-time scripts. The repository license conflicts with the manifest, and missing security tooling plus unpinned workflow actions reduce transparency and maintenance confidence.
68%
Total Score
75
100
81
75
The manifest declares MIT, but the repository license file was detected as GPL-3.0, creating an unresolved licensing mismatch. The repository does contain a license file, so this is a consistency concern rather than an absence of licensing.
The package has four releases over roughly four and a half years, with one release in the last year. This shows some ongoing publishing but a thin long-term release history.
The repository recorded zero commits and zero active maintainers in the last three months. That is a meaningful maintenance warning, although the repository is not archived and a release was published during the broader period.
Composer build tooling is present, but no security scanning tools were detected. The missing scanning is a transparency and hygiene gap, not evidence of unsafe code by itself.
The repository has no security policy. For a library that processes web content, this weakens the documented route for reporting vulnerabilities.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.