Usable with caveats: the package is licensed, stable, documented, and not deprecated, but its registry release history has been inactive for over three years. The linked repository is not archived, though it had no commits or active maintainers in the last three months, so verify compatibility before adopting it.
62%
Total Score
67
100
89
88
The package has 13 releases since April 2020, but none in the last three years; that is a meaningful maintenance concern for a dependency.
The repository recorded zero commits and zero active maintainers in the last three months, indicating that maintenance has currently stalled despite the repository not being archived.
There are no new issues or merged pull requests in the last month, with one pull request still open; this offers little evidence of active maintenance but is not severe alone.
Composer build tooling is present, but no security scanning tools are configured; for this small theme, that is a transparency gap rather than evidence of an unsafe release.
No security policy is provided, leaving vulnerability reporting expectations unclear; this is a modest transparency concern for a project with limited recent activity.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
twig/twig Version ^3.0 | — | — |
getkirby/cms Version ^3.9 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.