The MIT license, readable documentation, and substantial source tree make the package straightforward to inspect and adopt. Its limited testing and security process leave less evidence for long-term reliability.
61%
Total Score
50
88
75
The registry has one publishing maintainer; the linked repository is user-owned, so there is no organization backing shown to compensate for that concentration.
The package is 443 days old but has only two releases, with one release in the last 12 months and a median interval of about 374 days; this indicates a slow maintenance cadence.
One contributor made all recent commits, leaving the project dependent on a single active maintainer for ongoing changes.
Only one commit was recorded in the last three months, so there is recent activity but little evidence of sustained maintenance.
Composer is used as the build tool, but no security-scanning tools were detected, reducing the project's visible security hygiene.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
twig/twig Version ^3.19 | — | — |
rmunate/dian-colombia Version ^1.4 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.