The MIT declaration, matching repository, README, and clean install profile improve transparency. The single maintainer and absent security scanning leave limited independent assurance.
65%
Total Score
67
100
88
75
One registry maintainer account is responsible for publishing the package, leaving a thin publishing base for continuity if that maintainer becomes unavailable.
This package has existed for 296 days but has only one release, so there is little evidence of an established release process or sustained maintenance.
The repository had zero commits and zero active maintainers during the past three months, which is a meaningful sign of limited recent maintenance.
Composer is used for the build, but no security-scanning tools are configured, leaving less automated coverage for dependency and repository risks.
The repository has no security policy, so users have no documented reporting or response process for vulnerabilities.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
twig/twig Version ^3.19 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.