The README is present, the MIT license is declared, and installation has no lifecycle scripts. Its small footprint limits complexity, but no tests or security tooling reduce confidence.
40%
Total Score
25
75
75
The package has had no release in about 9 years: all four releases arrived in April 2017, with none in the last 12 months. This strongly indicates abandonment risk.
The repository shows zero commits and zero active maintainers in the last 3 months, consistent with the release history and leaving no evidence of ongoing maintenance.
Only one registry maintainer is listed, and the project is user-owned rather than organization-backed. That creates a thin publishing and continuity base.
The repository has 0 stars, 0 forks, and 1 watcher, providing little supporting evidence of broad review or community continuity. Popularity is supporting evidence, but this reinforces the maintenance concerns.
Composer is used for builds, but no security-scanning tool is present. The missing scanning is a modest hygiene gap alongside the broader maintenance concerns.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
twig/twig Version ^1.0||^2.0 | — | — |
symfony/symfony Version 3.2.* | — | — |
sensio/buzz-bundle Version 1.1.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.