The package is small and focused, with a clear README, matching repository, and straightforward Composer dependencies. Its maintenance record is too new to establish durability, and the repository has no security scanning or security policy.
62%
Total Score
50
100
86
88
One registry maintainer is listed, consistent with the matching personal repository owner, but there is no provided evidence of a broader maintainer base or sustained activity.
This is the first release, published today, so there is no release history or cadence demonstrating long-term maintenance. Its newness is a caution rather than evidence of abandonment by itself.
The repository has no commits or active maintainers in the last three months, which provides no established maintenance record; the repository is also newly created, limiting how strongly this weighs against it.
Composer is used as a build tool, which fits the package, but no security scanning tools were detected. That leaves a meaningful security-process gap for a dependency.
The repository has no security policy. This reduces transparency around vulnerability reporting, although it is not by itself evidence that the code is unsafe.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
twig/twig Version ^3.0 | — | — |
symfony/asset Version ^7.4 || ^8.0 | — | — |
contao/core-bundle Version ^5.7 || ^6.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.