The package is small and focused, with a clear README, matching repository, and no install-time scripts. Its maintenance evidence is too weak for a current dependency, with no recent activity and no security policy.
38%
Total Score
50
100
72
75
The latest release was published in November 2017, and there have been no releases in nearly nine years. The short initial release history does not compensate for this prolonged inactivity.
The repository recorded zero commits and zero active maintainers during the last three months. Combined with the old release date, this is strong evidence of abandonment risk.
There is one open issue and no issue or pull-request activity in the last month. This provides no evidence of active support.
The repository has four stars and four forks, indicating limited adoption. Popularity is supporting evidence only, but it provides little compensating evidence for the long maintenance gap.
The repository uses Composer, appropriate for this package, but no security scanning tools were detected. This is a modest transparency and maintenance gap, not a severe risk alone.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
twig/twig Version ^1.23.1 | — | — |
drupal/core Version ~8.4 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.