The package includes tests, a README, release notes, and a small dependency surface with no install scripts. Its repository is not archived, but it has little community activity and no security scanning.
42%
Total Score
25
100
75
75
This is the only release, published more than 10 years ago, with no releases in the last 12 months. That long period without a new release is strong evidence of abandonment risk.
The repository recorded no commits and no active maintainers in the last 3 months; its last push was in January 2017. This indicates maintenance has effectively stopped.
Two issues remain open, with no issues or pull requests opened or closed in the last month. Combined with the lack of recent commits, this suggests limited project responsiveness.
The repository has 0 stars and 0 forks, with only 2 watchers. Popularity is supporting evidence rather than a verdict, but these figures provide little evidence of a broad community to sustain the package.
The repository uses Composer for builds, providing basic project tooling, but no security scanning tools were found. The missing scanning is a modest transparency and maintenance gap.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
twig/twig Version ~1.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.