The package is documented and tested, with a clear MIT license and no install-time scripts. Maintenance appears stalled since May 2023, and all four workflow actions are unpinned, so future compatibility and build reproducibility need attention.
63%
Total Score
67
100
83
67
The package has had no releases in more than three years, despite three releases arriving within its first week. This supports a stable small package, but provides little evidence of ongoing maintenance.
There were no commits and no active maintainers in the last three months, consistent with a project that has been inactive for several years. This is the main adoption concern, though the package may be feature-complete.
There is one open issue and no recent issue or pull-request activity, offering no evidence of active support.
The repository has no stars or forks and only one watcher. Popularity is supporting evidence rather than a verdict, but these counters provide little evidence of a broad maintenance community.
Composer build tooling is present, but no security scanning tools are reported. The missing scanning is a modest transparency gap rather than evidence that the package is unsafe.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
twig/twig Version ^3.3 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.