The package has an MIT license, tests, and a small dependency set. Its documentation is minimal, and the repository has no security policy or automated workflow evidence. Pin v1.0.2 only if this narrow, aging component is still required.
38%
Total Score
50
100
67
88
The latest recorded release was over 7 years ago, with no releases in the preceding 12 months and only three releases overall. This is strong evidence of stalled maintenance.
The repository is not archived, which is a positive, but it was last pushed over 10 years ago. Its unarchived status does not compensate for that prolonged inactivity.
The repository is owned by an individual account rather than an organization. This does not establish a problem by itself, but it provides no organizational backing to offset the very old activity record.
The linked repository has no security policy. For an old package with little recent activity, that leaves vulnerability reporting and response expectations unclear.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
urmaul/url Version ~1.2 | — | — |
urmaul/rss-pipes Version ~1.4 | — | — |
symfony/dom-crawler Version ~3.0 | — | — |
symfony/css-selector Version ~3.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.