The package has a clear license, tests, README, matching organization repository, and no install scripts. It lacks a security policy and security scanning, leaving limited evidence of vulnerability-response readiness.
58%
Total Score
75
83
75
There have been only 5 releases since February 2022, with one release in the last 12 months and a median interval of about 16 months, indicating a slow maintenance cadence.
The repository recorded 0 commits and 0 active maintainers in the last 3 months, which weakens evidence of ongoing maintenance despite the recent release and push.
The repository has 0 stars and 0 forks, with 1 watcher. This is weak supporting evidence of adoption, though popularity alone does not determine whether a small package is healthy.
Composer build tooling is present, but no security-scanning tools were detected, reducing independent evidence of routine security checks.
No security policy is present, so the project provides no documented vulnerability-reporting process; this is a transparency and response-readiness gap.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
twig/twig Version ^3.29.0 | — | — |
yiisoft/yii2 Version ~2.0.42 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.