Tests, a changelog, an MIT license file, and no install-time scripts provide useful safeguards. The small dependency set helps limit exposure, but this release should not be adopted without a maintained alternative or a tightly controlled pin.
38%
Total Score
0
100
57
75
The package has only one release, published about 5 years ago, with no releases in the last 12 months. This is strong evidence of abandonment risk for a package intended as a dependency.
There were zero commits and zero active maintainers in the last 3 months, consistent with the repository having received no meaningful updates since 2021.
The package includes a README, tests, and a changelog, and the source repository also reports tests and a changelog. The README is short and marks substantial functionality and documentation as unfinished, which modestly limits consumer confidence.
The repository name matches the package, reducing the risk of an unrelated source repository, but the README does not mention the package name. That mismatch is a minor provenance concern.
The repository has 1 star, 0 forks, and 1 watcher. Popularity is only supporting evidence, but these figures provide little evidence of a broad user or contributor base.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
twig/twig Version >=2.14.0 | — | — |
symfony/framework-bundle Version >=4.0.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.