The only release was published nearly five years ago, and the linked repository does not match or clearly mention the package. The package also declares a proprietary license while containing an MIT license file, and its README describes Composer Semver rather than this package.
42%
Total Score
38
50
This package has only one release, published nearly five years ago, with no releases in the last 12 months. The repository is not archived, but the long period without another release is a substantial maintenance concern.
The manifest declares a proprietary license, while an MIT license file is detected in the artifact. The mismatch makes the terms under which consumers may use the package unclear despite the presence of a license file.
The artifact contains a README, tests, and a changelog, which is positive, but the README identifies Composer Semver rather than this package. That weakens documentation transparency for consumers.
The linked repository name does not match the package name, and the collected README mention is null. A mismatch can be normal for a sub-package, but here there is no provided evidence tying this repository clearly to the published package.
The linked repository has no security policy. For a small, inactive package this is an additional transparency gap, though it is less significant than the stale release history and package-identity concerns.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
phan/phan Version ^4.0 | — | — |
guzzlehttp/guzzle Version ^7.3 | — | — |
symfony/dom-crawler Version ^v5.2.4 | — | — |
symfony/css-selector Version ^v5.2.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.