Usable with caveats: this is a small, stable package with clear licensing, release notes, tests, and matching project backing. However, it has had no release or commit activity for over six years, so maintenance and compatibility risk should be considered before adoption.
60%
Total Score
88
100
78
90
The package has only two releases and none in over six years, indicating very limited release activity and a substantial risk that compatibility issues will not be addressed.
There were no commits or active maintainers in the last three months, reinforcing the concern that maintenance has effectively stopped.
The repository has three stars and one fork, showing limited adoption. Popularity is supporting evidence only, but this does not provide much external evidence of project maturity.
The repository uses Composer and Make tooling, but has no security scanning tools; this is a modest transparency gap for supply-chain maintenance.
The repository is not archived, but its last push was over six years ago, so the absence of archival does not offset the evidence of inactivity.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
twig/twig Version ^1.43 || ^2.13 || ^3.0 | — | — |
gravatarphp/gravatar Version ^2.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.