The package includes extensive documentation, tests, and a clear MIT license. Its single release, no recent commits, and one-person publishing base leave maintenance capacity unproven; the repository also lacks a security policy.
60%
Total Score
50
92
50
A single registry maintainer is a thin publishing base; the matching user-owned repository provides ownership continuity but does not establish redundancy.
There has been only one release, published 234 days ago, so there is no demonstrated release cadence or evidence of sustained maintenance.
The repository recorded zero commits and zero active maintainers in the last three months, which weakens confidence that issues and compatibility changes will be addressed.
The repository has no security policy, leaving no documented process for reporting and handling vulnerabilities in a security-sensitive integration package.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
twig/twig Version ^3.0|^4.0 | — | — |
symfony/yaml Version ^7.0|^8.0 | — | — |
symfony/console Version ^7.0|^8.0 | — | — |
symfony/process Version ^7.0|^8.0 | — | — |
symfony/twig-bundle Version ^7.0|^8.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.