It has tests, a useful README, and a small dependency surface. The MIT declaration conflicts with the detected GPL-3.0 license, while all recent commits come from one contributor and no security policy is provided.
60%
Total Score
75
83
75
The manifest declares MIT, but the artifact license file is detected as GPL-3.0; although a license exists, the mismatch creates legal uncertainty for consumers.
This is a young package, 88 days old, with only one release and no established release cadence. Its recent origin limits evidence of long-term maintenance.
One contributor accounts for all recent commits, leaving no demonstrated handoff capacity. The repository is user-owned rather than organization-owned, so this concentration is a genuine maintenance risk.
The repository has no security policy. This is a transparency and vulnerability-reporting gap, though the package's tests and active recent commits provide some compensating project evidence.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
twig/twig Version ^3.0 | — | — |
symfony/config Version ^8.0 | — | — |
symfony/http-kernel Version ^8.0 | — | — |
symfony/dependency-injection Version ^8.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.