The package is clearly licensed and has a focused dependency profile. Its only release was over 12 years ago, with no recent commits, tests, security policy, or meaningful adoption evidence; pinning this release carries substantial maintenance risk.
38%
Total Score
33
100
64
75
This is the package’s only release, published over 12 years ago, with no releases in the last 12 months. That strongly indicates the project is inactive.
The repository has recorded no commits and no active maintainers in the last three months, consistent with the release history and indicating no current maintenance.
One registry maintainer is consistent with an individual-owned project. It is not inherently concerning, but it leaves little visible redundancy if the maintainer is inactive.
The package and repository are owned by the same individual account. This provides coherent ownership, but no organizational backing is shown to compensate for inactivity.
The repository has zero stars and forks and one watcher, providing little evidence of community adoption or review.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
twig/twig Version >=1.12 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.