It includes a substantial tested codebase, matching repository, and MIT licensing. A single registry maintainer and no security policy reduce confidence for ongoing support.
58%
Total Score
50
90
50
Only one registry account has publish access. The organization-owned repository provides some backing context, but the narrow publishing base still reduces resilience.
The package has 264 releases since April 2020, but none in the last two years; that long release gap is a meaningful maintenance concern.
The repository recorded no commits and no active maintainers in the last three months, consistent with the extended release pause and increasing abandonment risk.
The repository has no published security policy, leaving vulnerability-reporting and response expectations unclear for a package with 24 runtime dependencies.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
phpgt/dom Version ^2.1 | — | — |
twig/twig Version ^2.5 | — | — |
latte/latte Version ^2.5 | — | — |
nette/utils Version ^2.5|^3.0 | — | — |
tracy/tracy Version ^2.5 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.