The package has a small dependency footprint, tests, and an MIT declaration. Its lack of recent activity and minimal public footprint make future fixes uncertain; pin this version only if its narrow functionality is already validated.
43%
Total Score
25
100
67
75
The latest release was published nearly five years ago, and there have been no releases in the last 12 months. This is strong evidence of abandonment risk despite the package having three releases overall.
There were no commits and no active maintainers in the last three months, reinforcing the release-history evidence that maintenance has stopped.
The artifact and repository include tests, and the exact version has a GitHub release. The missing README and changelog reduce transparency for a library consumers must integrate, although the tests provide some compensation.
The repository is owned by an individual account rather than an organization. That is not inherently unhealthy, but it offers no visible organizational backing to offset the inactive history.
The repository name does not match the package name, and the collected README reference is unknown. The mismatch makes package ownership less transparent, though it could still reflect a sub-package naming arrangement.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
twig/twig Version ^3.0 | — | — |
gvera/config Version ^1.3 | — | — |
gvera/exceptions Version ^1.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.