The repository includes tests, extensive documentation, and a source tree that matches the package. Missing security scanning and a single publisher reduce independent assurance, while the project has little community activity.
68%
Total Score
50
100
89
75
Only one registry publisher account is listed. The repository is user-owned rather than organization-backed, so there is limited visible publishing redundancy.
The registry namespace and repository owner are different user accounts, with no organization backing shown. This limits visible institutional continuity but does not by itself indicate abandonment.
There are no open issues or pull requests and no issue or pull-request activity in the last month, so there is little evidence of community engagement or independent maintenance.
The repository has zero stars, forks, and watchers, providing no community adoption or external review signal. This is supporting evidence rather than proof of poor quality.
Composer build tooling is present, but no security-scanning tool is configured, leaving less automated assurance around the published project.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
guzzlehttp/guzzle Version ^6.5|^7.5 | — | — |
symfony/dom-crawler Version ^5.4 | — | — |
symfony/css-selector Version ^5.4 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.