This release appears suitable to depend on, with strong repository transparency, a complete package tree, tests and changelog, active recent development, a stable 1.3.0 release, and organizational backing. The main reservations are that the package is only 60 days old, has no repository security policy or security-scanning tooling, has no CI workflows observed, and has not yet established meaningful popularity; these are maturity and process gaps rather than evidence of abandonment. The single registry maintainer is appropriately less concerning because the repository is owned by an organization and four contributors have been active recently.
82%
Total Score
100
100
83
90
Four releases in 60 days, with a median interval of about 3.7 days, show active publishing, but the short history means long-term maintenance is not yet established.
The repository has zero stars, forks, and watchers, so there is little external adoption evidence; however, the package is very young and active maintenance provides stronger evidence than popularity alone.
Composer build tooling is present, but no security-scanning tools were detected, leaving a process gap in dependency and code security assurance.
The repository has no security policy, reducing the transparency of vulnerability reporting and response procedures.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
twig/twig Version ^3.0 | — | — |
symfony/yaml Version ^6.4 || ^7.0 | — | — |
symfony/routing Version ^6.4 || ^7.0 | — | — |
symfony/ux-turbo Version ^2.13 | — | — |
symfony/ux-twig-component Version ^2.13 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.