Package Health

jacerider/neo_twig

The package is well documented and tested, and its repository is active rather than archived. Its low popularity and absent security policy provide little extra assurance.

Latest 1.0.26PackagistPackagist

68%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

75

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

86

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

75

Health Score Breakdown

Licensecaution

The manifest declares a proprietary license, so licensing terms are explicit but may restrict use in projects expecting an open-source dependency. No license file was detected to provide additional clarity.

Repo bus factorcaution

All 40 recent commits came from one contributor, leaving maintenance dependent on a single person. The repository is user-owned rather than organization-backed, so there is no shown handoff capacity to offset that concentration.

Repo toolingcaution

Composer is used for builds, but no security scanning tool was detected. This is a modest transparency and maintenance gap, not evidence of unsafe behavior by itself.

Security policycaution

The repository has no security policy, leaving vulnerability reporting and response expectations undocumented. This is a hygiene gap for a dependency.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

Cyle Carlson (JaceRider)

Direct Dependencies

DependencyLast ReleaseScore
drupal/core
Version ^10.3 || ^11

Weekly Downloads

Info

Last Published
20 days ago
Created
2 years ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform