The README and release notes provide useful consumer guidance. The repository is small and lacks security-policy coverage, so pinning this old release deserves caution.
42%
Total Score
25
70
75
The package has had no releases in over two years despite 20 releases overall, indicating substantial abandonment risk for a framework dependency.
The repository recorded no commits and no active maintainers in the last three months; together with the old latest release, this strongly lowers maintenance confidence.
Only one registry account has publish access, leaving a thin publishing base; the linked repository is user-owned, so this is a real but moderate continuity concern.
The repository name matches the package, but its README does not mention the package name, leaving some uncertainty about package-to-repository alignment.
The repository has no security policy, reducing transparency for reporting and handling vulnerabilities in a web framework.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
twig/twig Version ^3.0 | — | — |
symfony/string Version ^7.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.