Usable with caveats: it has a stable release, complete source tree, tests, and organization backing. It is still a young project with only three releases, no commits in the last three months, and limited security process.
68%
Total Score
88
100
83
90
The package is only 252 days old with three releases, spaced a median of about 126 days apart. The latest release was published recently, but the limited history provides only moderate evidence of long-term maintenance.
There were zero commits and zero active maintainers in the last three months. The same-day release and repository push provide some recent activity, but the lack of sustained commit activity is a real maintenance concern.
The repository has four stars, no forks, and no watchers. This is limited supporting evidence of community adoption, but popularity alone does not make a small, maintained package unhealthy.
Composer build tooling is present, but no security scanning tool is configured. This is a process gap for supply-chain transparency, though it is not by itself evidence that the package is unsafe.
No security policy is provided. For a package that parses and renders templates, the absence reduces the transparency of vulnerability reporting and response practices.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.