The source is identifiable, licensed, and free of install-time scripts. Its last release and repository activity were about 10 years ago, while the README still marks usage as TODO and no security policy is present.
38%
Total Score
0
79
75
The package has 20 releases but none in the last 12 months; its latest release was about 10 years ago. This is strong evidence of abandonment despite its long history.
The repository recorded 0 commits and 0 active maintainers in the last 3 months, consistent with the release gap and indicating no current maintenance capacity.
A README is included, but it is only 787 characters and leaves usage marked “todo.” Missing tests and a changelog are normal for a published artifact, so the main concern is incomplete consumer documentation.
The linked repository has no security policy. This is a transparency gap for a package with no recent maintenance activity, although it does not by itself show an active security problem.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
twig/twig Version 1.9.* | — | — |
yalesov/yaml Version 2.* | — | — |
twig/extensions Version 1.0.*@dev | — | — |
kriswallsmith/assetic Version 1.* | — | — |
yalesov/arg-validator Version 2.* | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.