Healthy and reasonable to depend on, with some maintenance-process caveats. It has a long release history, a recent release, tests, documentation, active repository tooling, and no deprecation or archive status. Recent work is concentrated in one contributor, and the repository lacks a security policy and explicit workflow token permissions.
78%
Total Score
50
94
80
The repository is owned by an individual account rather than an organization. That is compatible with a healthy small project, but it provides no organizational redundancy to offset the concentrated recent activity.
One contributor made all 3 recent commits, giving the project a very high short-term concentration risk. The repository is individually owned, so there is no shown organizational backing to compensate for this.
There were 3 commits in the last 3 months, showing recent work, but all activity came from only one active maintainer. The cadence is adequate but not broad.
The repository has no security policy. This is a transparency and vulnerability-reporting gap, though it is not by itself evidence that the package is unsafe to use.
Neither workflow declares top-level token permissions, although no workflow requests top-level write access and one uses job-level permissions. Explicit least-privilege declarations would make the CI supply chain clearer.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
vdb/uri Version ^0.3.2 | — | — |
symfony/finder Version ^3.0.0||^4.0.0||^5.0.0||^6.0||^7.0||^8.0 | — | — |
guzzlehttp/guzzle Version ^6.0||^7.0||^8.0 | — | — |
spatie/robots-txt Version ^2.0 | — | — |
symfony/dom-crawler Version ^3.0.0||^4.0.0||^5.0.0||^6.0||^7.0||^8.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.