The package is small and easy to inspect, with a clear README, a declared license, and one runtime dependency. Its single release was published about 3 years and 9 months ago, with no commits or active maintainers in the last 3 months, making abandonment a serious concern.
43%
Total Score
0
100
71
83
This is the package's only release, published about 3 years and 9 months ago, with no releases in the last 12 months. The stable version lowers change risk, but the lack of any follow-up release is a strong abandonment concern.
The repository recorded 0 commits and 0 active maintainers in the last 3 months. With only one release, there is no observed recent maintenance to offset that inactivity.
The repository has 0 stars and 0 forks, with 1 watcher. This provides little evidence of community adoption or review, though low popularity alone is not decisive for a small package.
Composer is used for the build, but no security-scanning tools are present. The simple build setup is appropriate, while the missing scanning is a minor transparency and hygiene gap.
The repository has no security policy. For a package intended to sanitize HTML, this reduces transparency around vulnerability reporting and handling.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
yiisoft/yii2 Version >=2.0.6 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.