This is Symfony bundle which extends the twig implementation by an JSX like syntax.
42%
Total Score
75
79
67
Packagist marks the entire package as abandoned, which is a major adoption concern even though a linked replacement is named and the repository remains available.
The package has 11 releases over about four years, but none in the last 12 months; the last registry release was about one year ago, indicating stalled publishing.
The repository recorded zero commits and zero active maintainers over the last three months, a strong sign of currently inactive development despite other repository activity.
No security policy was found in the repository, leaving vulnerability-reporting and response expectations undocumented.
Both workflows were analyzed successfully with no dangerous triggers, untrusted checkouts, script injections, or audit findings. One of seven action references is unpinned, a minor reproducibility concern.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
twig/twig Version ^3.0.0 | — | — |
symfony/config Version ^5.4 || ^6.4 || ^7.2 | — | — |
symfony/http-kernel Version ^5.4 || ^6.4 || ^7.2 | — | — |
symfony/http-foundation Version ^5.4 || ^6.4 || ^7.2 | — | — |
symfony/dependency-injection Version ^5.4 || ^6.4 || ^7.2 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.