Package Health

wikimedia/html-formatter

Performs transformations of HTML by wrapping around libxml2 and working around its countless bugs.

Latest 4.1.0PackagistPackagist

64%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

83

Dependencies
Dependencies
Evaluates the health and security of package dependencies

100

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

80

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

83

Health Score Breakdown

Name lookalikecaution

The signal reports identity borrowing toward wikimedia/utfnormal, but artifact overlap is moderate at 0.5 rather than near-total and the lookalike is in the same Wikimedia namespace. This warrants caution, not a conclusion that consumers wanted the other package.

Release historycaution

The package has 12 releases since April 2016, but none in the last 12 months and the latest release was in March 2024. That is a meaningful maintenance concern for a library dependency.

Repo commit activitycaution

The repository recorded zero commits and zero active maintainers in the last three months. Combined with no registry releases in the last 12 months, this raises concern about current maintenance capacity.

Repo package mentioncaution

The repository name does not exactly match the package name and its README does not mention the package. This is a transparency concern, although the repository owner and HtmlFormatter source name provide some compensating context.

Repo toolingcaution

Composer build tooling is present, but no security scanning tools were detected. The missing scanning is a hygiene gap rather than evidence of abandonment.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

MediaWiki contributors

Direct Dependencies

No direct dependencies.

Weekly Downloads

Info

Last Published
2 years ago
Created
10 years ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform