The package includes clear usage documentation, a stable release, and a matching organization-backed repository. Recent repository activity is absent, and no security policy or scanning tooling is provided, so maintenance and response capacity warrant caution.
68%
Total Score
67
100
89
83
The package has existed for over four years with 16 releases, but only one release in the last 12 months. The latest release is recent, so this indicates slower cadence rather than abandonment.
The repository has had zero commits and zero active maintainers in the last three months. Although a recent release exists, this is a meaningful maintenance-capacity warning.
No issues or pull requests were opened or closed in the last month, with four open issues and two open pull requests. This supports the indication of limited recent activity.
Composer is used as a build tool, but no security scanning tools are configured. The missing scanning is a modest transparency and maintenance gap.
The repository has no published security policy, leaving vulnerability reporting and response expectations unclear.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
erusev/parsedown Version 1.8.0-beta-7 | — | — |
nikic/php-parser Version 5.3.1 | — | — |
phpdocumentor/reflection-docblock Version 5.5.1 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.