Recent development is limited to three commits by one contributor in three months, and the linked repository does not identify this package. The repository has tests, a clear license, and recent releases, but the package should not be chosen over its stated replacement.
35%
Total Score
50
71
83
Packagist marks the entire package as abandoned and names open-function-computers-llc/rad-theme-engine as its replacement, making this release a poor choice for a new dependency.
All three recent commits came from one contributor. Organization ownership provides some handoff capacity, but no second active contributor is shown.
Only three commits were made in the last three months, indicating limited recent maintenance activity even though the repository was updated recently.
The linked repository is named rad-theme-engine and does not mention this package in its README, so the package-to-repository relationship is not transparently established.
Composer and Make are used for project tooling, but no security scanning tools are reported, leaving a modest security-process gap.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
symfony/yaml Version ^7.4 | — | — |
jjgrainger/posttypes Version ^2.2 | — | — |
enshrined/svg-sanitize Version ^0.22.0 | — | — |
salesforce/handlebars-php Version ^2.3 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.