Package Health

voku/anti-xss

anti xss-library

Latest 4.1.45PackagistPackagist

74%

Total Score

caution

Long-term maintenance is active, but nearly all recent commits come from one contributor and CI needs workflow-hygiene attention.

Health Score Breakdown

Project backingcaution

The registry namespace and repository are owned by the same individual account, so there is no organizational backing shown to offset the concentrated contributor activity.

Repo bus factorcaution

Although two contributors were active, one contributor made 51 of 52 recent commits, leaving maintenance highly concentrated and increasing continuity risk.

Security policycaution

No repository security policy was found. For a package focused on filtering XSS, the absence of a documented vulnerability-reporting process is a transparency gap.

Workflow auditcaution

The single workflow was fully analyzed, uses read-only permissions, and pins all seven action references. However, it contains three high-confidence template-injection findings; template injection alone is a workflow-hygiene concern rather than evidence of an untrusted checkout or dangerous trigger.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

EllisLab Dev Team
Lars Moelleken

Direct Dependencies

DependencyLast ReleaseScore
voku/portable-utf8
Version ~6.1.0
—
—

Weekly Downloads

Info

Last Published
1 day ago
Created
11 years ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform