The package is small and straightforward, with a clear README, MIT license, and no install-time scripts. Its repository has had no commits or issue activity in the observed period, and it has no security policy or scanning tools.
58%
Total Score
38
100
88
88
The repository recorded zero commits and zero active maintainers over the last three months, consistent with the long gap since the latest release and increasing abandonment risk.
One registry publisher is consistent with a user-owned project, especially since the repository owner is also a user account; this is limited redundancy but not independently severe.
The repository owner is a user account rather than an organization, so the single publisher and lack of recent activity are not offset by visible organizational backing.
The package has a long history and 35 releases, but the latest release was on February 20, 2023, with no releases in the last 12 months; this materially raises abandonment risk.
There are 31 open issues and 3 open pull requests, but no new or closed issues or pull requests in the observed month, suggesting unattended maintenance.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
twig/twig Version ^2.0 || ^3.0 | — | — |
gregwar/image Version 2.* | — | — |
symfony/asset Version * | — | — |
symfony/framework-bundle Version ^2.3 || ^3.0 || ^4.0 || ^5.0 || ^6.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.