Package Health

wyrihaximus/html-compress

Repository tests, release notes, licensing, and a non-archived source provide useful maintenance and transparency evidence. Recent registry and commit activity are limited, while install scripts and workflows with broad write access and unpinned actions add operational risk.

Latest 4.4.0PackagistPackagist

61%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

50

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

88

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

50

Health Score Breakdown

Lifecycle scriptscaution

The package runs post-install and post-update scripts, creating extra install-time behavior that dependencies without lifecycle hooks would not require.

Project backingcaution

The source is owned by an individual rather than an organization, so the single registry maintainer provides limited visible backing; this is a modest resilience concern, not evidence of abandonment by itself.

Release historycaution

The package has a long history and 21 releases, but it had no registry releases in the last 12 months as of collection, indicating a slower release cadence.

Repo commit activitycaution

The repository recorded zero commits and zero active maintainers in the last 3 months, which is a concrete sign of currently limited development activity.

Repo toolingcaution

The project uses Composer and Make, but no security-scanning tooling was detected, leaving a modest maintenance and review gap.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

Cees-Jan Kiewiet

Direct Dependencies

DependencyLast ReleaseScore
voku/html-min
Version ^4.5.1
voku/simple_html_dom
Version ^4.8.9
wyrihaximus/compress
Version ^2.0
thecodingmachine/safe
Version ^2.2 || ^3.0
wyrihaximus/js-compress
Version ^5

Weekly Downloads

Info

Last Published
1 year ago
Created
11 years ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform