The license conflict makes redistribution and compliance unclear. A missing security policy and absent repository security tooling add transparency concerns, while the repository remains linked and unarchived.
39%
Total Score
0
64
50
The package has 33 releases but none in the last four years; its latest release was in September 2022, which is a substantial abandonment risk despite its earlier release history.
The repository recorded zero commits and zero active maintainers in the last three months, consistent with the long registry pause and leaving no evidence of current maintenance.
The manifest declares MIT, but the artifact license file is detected as GPL-3.0; although license files exist in both the artifact and repository, the mismatch creates a real compliance concern.
The repository has zero stars and forks and only one watcher, providing little evidence of external review or community support. Low popularity is supporting caution rather than a verdict by itself.
Composer build tooling is present, but no security scanning tools are configured. That leaves dependency and code issues less likely to be detected, though it is not evidence of malicious behavior.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
twig/twig Version ^3.4 | — | — |
symfony/console Version ^v6.1 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.