It has a clear MIT license, a README, tests, and no install-time scripts. Its small dependency set and matching repository provide useful transparency, but they do not offset the lack of ongoing maintenance.
35%
Total Score
50
100
69
75
The package has had no releases in the last 12 months, and both its latest release and first release date to August 2017. This long period without updates is strong evidence of abandonment risk.
The source repository is owned by an individual user rather than an organization, so there is no demonstrated organizational backing to compensate for the single-publisher and inactive-project signals.
There were no new issues, closed issues, or pull requests in the last month, and no pull requests were open. This is consistent with the repository's long inactivity, although the null open-issue count limits the evidence.
The repository has zero stars, forks, and watchers. Popularity is only supporting evidence, but these counters provide no community-maintenance signal to offset the stale release history.
Composer is used as the build tool, which fits the Packagist ecosystem. No security-scanning tooling was detected, leaving a minor transparency gap, but this is secondary to the maintenance evidence.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
laravel/framework Version 5.4.* | — | — |
symfony/dom-crawler Version 3.1.* | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.