Healthy and suitable to use, with the normal caution of a young pre-1.0 package. It has recent releases, active work from two contributors, tests in the repository, and clear release notes; the main gaps are its limited track record and missing security policy.
82%
Total Score
100
100
78
90
The package is only 82 days old and has two releases, with a median interval of about 54 days. That is limited evidence of long-term maintenance, though the latest release is recent.
The repository has only 3 stars and no forks or watchers, so there is little independent adoption evidence. Low popularity is only supporting evidence and is outweighed here by recent commits and organizational backing.
Composer build tooling is present, but no security scanning tools were detected. This weakens automated security-maintenance transparency without indicating abandonment.
The repository has no security policy, leaving vulnerability reporting and disclosure expectations unspecified. The omission is a transparency gap, not evidence that the package is unsafe.
Version v0.2.1 is not yet a stable major release, so APIs and behavior may change before 1.0. It is not marked as a prerelease, which partly offsets the concern.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
twig/twig Version ^3.21 | — | — |
symfony/asset Version ^8.1 | — | — |
symfony/config Version ^8.1 | — | — |
symfony/http-kernel Version ^8.1 | — | — |
symfony/twig-bundle Version ^8.1 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.