The package includes a clear README, tests, release notes, matching repository, MIT licensing, and automated dependency scanning. Its release history is stale and all six workflow action references are unpinned, so maintenance and build reproducibility need caution.
68%
Total Score
75
100
94
75
The latest registry release was over two years ago, with no releases in the last 12 months. This is a meaningful maintenance concern, although the package has a multi-year history and nine releases overall.
There were no commits and no active maintainers in the three months measured. This weakens evidence of current maintenance, even though the repository was pushed recently.
No repository security policy was found. This is a transparency gap, but it is not severe enough to outweigh the package's other documentation and project evidence.
Both workflows were analyzed without audit failures or dangerous triggers, but all six action references are unpinned. That leaves build inputs exposed to future action changes and is a reproducibility hygiene concern.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
twig/twig Version ^2.0|^3.0 | — | — |
symfony/form Version ^5.4|^6.0 | — | — |
symfony/asset Version ^5.4|^6.0 | — | — |
symfony/twig-bridge Version ^5.4|^6.0 | — | — |
symfony/framework-bundle Version ^5.4|^6.0|^7.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.