The package includes tests, a README, release notes, and no install-time scripts. Its maintenance has stopped, and the registry marks the package abandoned with no replacement, making adoption a liability.
20%
Total Score
0
57
100
Packagist marks the entire package as abandoned, with no replacement package provided. This is a severe adoption risk because the registry explicitly signals that ongoing support should not be expected.
The latest release was published on March 29, 2015, with no releases in the past 12 months; the package is about 11 years old. This strongly indicates abandonment rather than an actively maintained stable release.
The repository recorded zero commits and zero active maintainers in the past 3 months, consistent with the package's long release gap. This leaves little evidence of current maintenance capacity.
The linked repository neither matches the package name according to the indicator nor mentions the package in its README, creating some uncertainty about repository ownership and package transparency.
The linked repository is not archived, but it was last pushed on April 9, 2015. The non-archived status offers limited compensation for the absence of recent activity.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
twig/twig Version 1.* | — | — |
moss/locale Version 2.* | — | — |
moss/framework Version >=1.2 | — | — |
twig/extensions Version 1.* | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.