The project has a clear README, release notes, a matching repository, and a recent stable release. Missing security scanning and an unpinned two-action workflow leave maintenance and build hygiene weaker than ideal.
65%
Total Score
50
50
88
67
The package has 10 runtime dependencies, including HTTP, templating, and console components; this is a meaningful dependency surface but not unusually large for its stated functionality.
The repository is owned by an individual user rather than an organization. This is normal for a small project but provides less visible institutional backing for continuity.
The repository recorded zero commits and zero active maintainers in the last three months. Despite the recent push and release history, this is a concrete sign of currently limited maintenance activity.
There are eight open issues, with no issues or pull requests opened or closed in the last month. This suggests limited recent community activity, though it does not by itself establish abandonment.
The repository has zero stars, forks, and watchers. Popularity is only supporting evidence, but the absence of community adoption provides little external resilience if maintenance stops.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
twig/twig Version ^3.23.0 | — | — |
php-di/php-di Version ^7.1.1 | — | — |
guzzlehttp/psr7 Version ^2.8 | — | — |
symfony/console Version ^8.0.7 | — | — |
guzzlehttp/guzzle Version ^7.10 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.