Repository tests, release notes, licensing, and a non-archived source provide useful maintenance and transparency evidence. Recent registry and commit activity are limited, while install scripts and workflows with broad write access and unpinned actions add operational risk.
61%
Total Score
50
88
50
The package runs post-install and post-update scripts, creating extra install-time behavior that dependencies without lifecycle hooks would not require.
The source is owned by an individual rather than an organization, so the single registry maintainer provides limited visible backing; this is a modest resilience concern, not evidence of abandonment by itself.
The package has a long history and 21 releases, but it had no registry releases in the last 12 months as of collection, indicating a slower release cadence.
The repository recorded zero commits and zero active maintainers in the last 3 months, which is a concrete sign of currently limited development activity.
The project uses Composer and Make, but no security-scanning tooling was detected, leaving a modest maintenance and review gap.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
voku/html-min Version ^4.5.1 | — | — |
voku/simple_html_dom Version ^4.8.9 | — | — |
wyrihaximus/compress Version ^2.0 | — | — |
thecodingmachine/safe Version ^2.2 || ^3.0 | — | — |
wyrihaximus/js-compress Version ^5 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.