The MIT license, tests, release notes, and matching repository provide useful transparency. Packagist marks the package abandoned, and there were no releases since January 2024 or commits in the last three months, despite the repository remaining unarchived.
38%
Total Score
50
71
67
Packagist marks the package as abandoned at package scope, with no distinct replacement identified. This is a major adoption risk even though the repository is not archived.
The package has nine releases over more than 13 years, but none in the last 12 months; the latest release was in January 2024. That weakens confidence in ongoing maintenance.
The repository recorded zero commits and zero active maintainers in the last three months. The unarchived repository provides some context, but does not offset the lack of recent development activity.
The repository has no security policy, leaving vulnerability reporting and disclosure expectations unclear. This is a secondary transparency gap rather than evidence of abandonment by itself.
Both workflows were analyzed without high-confidence findings or dangerous triggers, but all six action references are unpinned. That weakens build reproducibility and supply-chain hygiene.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
twig/twig Version ^2.0|^3.0 | — | — |
symfony/form Version ^5.4|^6.0 | — | — |
symfony/asset Version ^5.4|^6.0 | — | — |
symfony/twig-bridge Version ^5.4|^6.0 | — | — |
symfony/framework-bundle Version ^5.4|^6.0|^7.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.