The package is clearly licensed, documented, and backed by the matching Bolt organization, with a small dependency surface and no install-time scripts. Maintenance evidence is limited, and the repository has no security policy, so pinning this version is sensible.
62%
Total Score
75
100
88
75
The package has 54 releases and historically released about every 15 days, but it has had no registry release in the last 12 months; the latest release was in April 2023, roughly three years and five months ago. This is a meaningful maintenance concern, partly offset by the repository being pushed in December 2025.
There were zero commits and zero active maintainers in the last three months. For a package with no recent registry releases, this weakens evidence of ongoing maintenance, although the December 2025 push is a partial counter-signal.
The repository uses Composer for builds, but no security-scanning tools were detected. The missing scanner is a hygiene gap rather than evidence that the release is unsafe.
The repository has no security policy. That reduces transparency about vulnerability reporting and response, though it is not by itself evidence of abandonment.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
twig/twig Version ^2.12 | ^3.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.