The MIT declaration, readable README, and GitHub release notes improve transparency. Its small repository footprint is less important than the lack of activity since 2016, so pinning this version leaves you with an aging dependency.
38%
Total Score
50
67
75
The package has had no release in nearly 10 years: its latest release was July 2016, with zero releases in the last 12 months. This is strong evidence of abandonment risk.
There were zero commits and zero active maintainers in the last three months, with the repository last pushed in 2016. This indicates that maintenance capacity has effectively disappeared.
The repository has zero stars and forks and only one watcher. Popularity is supporting evidence rather than a verdict, but these counters provide little evidence of a broad active user base.
Composer is used for the build, which fits the package ecosystem, but no security scanning tools were detected. That is a hygiene gap, not evidence that the package is unsafe.
The linked repository is not archived, so it remains administratively available. However, its last push was in July 2016, which is consistent with the maintenance concern shown by the release history.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
puli/discovery Version @beta | — | — |
puli/repository Version ^1.0@beta | — | — |
puli/url-generator Version @beta | — | — |
puli/twig-extension Version @beta | — | — |
puli/composer-plugin Version @beta | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.