Package Health

xemlock/htmlpurifier-html5

HTML5 support for HTML Purifier

Latest v0.1.12PackagistPackagist

68%

Total Score

caution

Usable with caveats: no commits in three months and both workflow actions are unpinned.

Health Score Breakdown

Lifecycle scriptscaution

The package declares post-install and post-update Composer scripts. Install-time scripts increase dependency-on-install exposure, although this signal alone does not show that the scripts perform unsafe actions.

Repo commit activitycaution

The repository had zero commits and zero active maintainers in the last three months. A recent release helps, but the absence of recent development activity is a maintenance concern.

Security policycaution

The repository has no security policy, leaving vulnerability reporting and response expectations unclear. Dependabot provides some compensating maintenance tooling but does not replace a published process.

Workflow auditcaution

The workflow audit completed cleanly with no dangerous triggers, sinks, or audit findings, but both analyzed action references are unpinned. That weakens build reproducibility and update control without indicating an immediate severe risk.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

xemlock

Direct Dependencies

DependencyLast ReleaseScore
ezyang/htmlpurifier
Version ^4.8
—
—

Weekly Downloads

Info

Last Published
7 months ago
Created
9 years ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform