This is a well-established, transparently maintained package with releases dating back to 2017, 48 releases, a recent release, an active non-archived organization-owned repository, clear licensing, and appropriate Composer and security-scanning tooling. The main concern is that no commits or active maintainers were observed in the last 3 months, despite the recent release, and the repository has no tests or security policy; these gaps modestly increase maintenance and transparency risk, but the package's small tooling scope, changelog, recent release activity, and project backing provide meaningful compensation.
78%
Total Score
88
100
89
90
A README and changelog are present, and the package is a small tooling collection; the absence of tests in both the artifact and repository is a modest hygiene gap but not decisive for this scope.
No commits and no active maintainers were observed in the last 3 months, a meaningful maintenance concern; the very recent release and repository push provide partial compensation but do not establish sustained activity.
The repository has no security policy, reducing transparency about vulnerability reporting and response expectations; the presence of Semgrep security scanning partly offsets this gap.
Version 0.8.4 is not a stable major release, which signals some API maturity risk, but it is a normal release rather than a prerelease and recent prerelease share is zero.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
twig/twig Version ^3.3 | — | — |
symfony/console Version ^5.4 || ^6.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.