The package has a clear README, tests, a stable release, and a small runtime dependency surface. Maintenance stopped after 2021, and both workflow references are unpinned; adopt only if its unchanged functionality meets your needs.
56%
Total Score
50
100
93
50
The package has only two releases, both published in April 2021, and none in the last 12 months. This is a meaningful maintenance concern for a library dependency, although a stable, narrow-purpose package may require few changes.
The repository recorded zero commits and zero active maintainers in the last three months, consistent with no releases since 2021. The lack of recent development increases abandonment risk.
The repository has no security policy or documented reporting path. This reduces transparency and supportability, though it is less concerning for a small, narrowly scoped integration.
The single workflow was fully analyzed with no dangerous triggers, untrusted checkouts, or audit findings, but both action references are unpinned. This is a supply-chain hygiene weakness without evidence of an active workflow exploit.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
twig/twig Version ^3.3 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.