There is no security policy, and registry publishing is handled by one person. The repository is clearly tied to the package and includes tests, a changelog, a README, and an active license.
42%
Total Score
25
100
75
75
The package has 30 releases but none in more than four years; the latest release was in July 2022, which is a strong maintenance concern for a library described as early development.
The repository recorded zero commits and zero active maintainers in the last three months, reinforcing the release-history evidence of stalled maintenance.
Only one account has registry publishing access. Because the repository is user-owned rather than organization-backed, this represents a thin publishing base and increases continuity risk.
The project uses Composer, but no security-scanning tools were detected. This is a hygiene gap rather than evidence that the package is unsafe to depend on.
The repository has no SECURITY.md or other security policy, leaving vulnerability-reporting and response expectations undocumented for a library handling form input.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
webtheory/html Version @stable | — | — |
myclabs/php-enum Version ^1.7 | — | — |
psr/http-message Version ^1.0 | — | — |
jawira/case-converter Version ^3.4 | — | — |
webtheory/http-policy Version @stable | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.