The small four-file repository has no tests or security scanning, though it does include a useful README and a declared MIT license. Its two runtime dependencies are limited, but the project offers little evidence of current maintenance or operational maturity.
38%
Total Score
0
100
78
75
The latest release was published in August 2018, and there have been no releases in more than eight years. Seven total releases show an established initial history, but the prolonged release gap strongly raises abandonment risk.
The repository recorded zero commits and zero active maintainers in the last three months, consistent with its last push in August 2018. This is strong evidence that maintenance has stopped.
The package and repository each contain only four files: a manifest, README, ignore file, and one source file. That compact structure may suit a small utility, but it leaves little evidence of testing, documentation depth, or ongoing project infrastructure.
The repository has zero stars, forks, and watchers, providing no supporting evidence of community adoption or review. Popularity is only supporting evidence, so this reinforces rather than determines the maintenance concerns.
Composer is used as the build tool, which is appropriate for this package. No security-scanning tooling is present, a modest transparency and maintenance gap for a project that has otherwise seen no recent activity.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
twig/twig Version ^2.4 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.