Twig extension for code highlighting using highlight.php
67%
Total Score
caution
Usable with caveats: nearly two years without a release and all workflow actions are unpinned.
The latest release was nearly two years ago, with no releases in the last 12 months and only three releases overall. This indicates slow maintenance, although the linked repository was pushed more recently.
There were no commits or active maintainers in the measured three-month period. This is a meaningful maintenance concern, though the repository's more recent push shows it is not wholly dormant.
The repository uses Make and Composer but reports no security-scanning tools. That is a modest engineering-hygiene gap rather than a severe dependency risk.
The repository has no security policy, leaving vulnerability-reporting and response expectations undocumented. This modestly reduces transparency for a package intended for application integration.
The workflow audit analyzed all workflows with no dangerous triggers, untrusted checkouts, or audit findings, but all six action references are unpinned. The complete audit limits the concern to reproducibility and action-supply-chain hygiene.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
twig/twig Version ^3.7 | — | — |
scrivo/highlight.php Version ^9.18 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.