The package includes tests, a substantial README, and a release note for this version. Its MIT declaration and focused dependency set are positives, but ongoing maintenance and security transparency remain limited.
62%
Total Score
63
100
83
75
One registry maintainer is consistent with a small user-owned project, but it provides limited publishing redundancy.
The repository is owned by an individual rather than an organization, so the single-maintainer and low-activity concerns are not offset by visible organizational backing.
There were no commits and no active maintainers in the last three months, indicating that maintenance has currently stopped.
The repository has zero stars, forks, and watchers. This is weak supporting evidence, but popularity alone does not establish abandonment.
Composer build tooling is present, but no security-scanning tools were detected, leaving security hygiene less transparent.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
twig/twig Version ^1 || ^2 || ^3 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.