The package is licensed, documented, and has no install-time scripts. Its small single-owner project has had no commits or releases for about 20 months, and all three workflow actions are unpinned; verify continued ownership before adopting.
58%
Total Score
50
93
67
One registry account publishes the package. Because the repository is user-owned rather than organization-backed, this indicates a thin maintainer base and limited continuity.
The package has 11 releases since June 2022, but none in the last 12 months and the latest release was about 20 months ago. This weakens confidence in ongoing maintenance.
There were zero commits and zero active maintainers in the last three months, consistent with the long release gap and indicating a real maintenance concern.
The repository has no security policy. This is a transparency and vulnerability-reporting gap, though it is less severe than abandonment or a deprecated release.
The complete audit found no dangerous triggers, untrusted checkouts, script injection, or high-confidence findings. However, all three action references are unpinned, leaving the workflow exposed to upstream action changes.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
twig/twig Version ^3.0 || ^2.0 || ^1.3 | — | — |
league/plates Version ^3.0 || ^2.0 || ^1.0 | — | — |
nguyenanhung/html-helper Version ^3.0 || ^2.0 || ^1.0 | — | — |
nguyenanhung/escape-helper Version ^3.0 || ^2.0 || ^1.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.