Healthy and reasonable to depend on, with a long release history, recent release, matching repository, thorough documentation, and established testing and tooling. Maintenance is currently concentrated in one contributor, and the repository lacks a security policy and explicit workflow token permissions.
78%
Total Score
63
50
100
80
The package declares nine runtime dependencies, including several voku libraries and encryption or validation components. This is a meaningful dependency surface but not, by itself, evidence of poor package health.
All one recent commit was made by a single contributor, so current maintenance has a narrow bus factor and limited demonstrated handoff capacity.
Only one commit was recorded in the last three months and it came from one active maintainer. Recent work exists, but the low volume is a maintenance concern for a library consumers may rely on.
There are no open issues and one open pull request, but no issues or pull requests were newly created or merged in the last month, showing limited recent collaboration activity.
The repository has no security policy, leaving vulnerability reporting and disclosure expectations undocumented despite the package being a reusable library.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
voku/arrayy Version ~7.8 | — | — |
voku/urlify Version ~5.0 | — | — |
voku/anti-xss Version ~4.1 | — | — |
voku/email-check Version ~3.1 | — | — |
voku/portable-utf8 Version ~6.1.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.