The organization-backed repository is active, correctly linked, and includes a useful README and tests. Recent work is sparse, this is an alpha release, and the workflow audit found high-confidence injection hygiene concerns.
62%
Total Score
67
92
75
All recent commits came from one contributor, creating concentration risk; organization ownership provides some capacity for handoff but no second active contributor is shown.
Only 1 commit from 1 active maintainer was recorded in the last 3 months, indicating sparse recent maintenance despite the package's longer release history.
The linked repository has no security policy, leaving vulnerability-reporting and response expectations undocumented.
The assessed release is v8.0.0-alpha.2 while the reported latest version is v5.2.1, so this pre-release should be treated as less stable than a mature stable release.
The sole workflow was fully analyzed and has no dangerous trigger or untrusted checkout, but its only action use is unpinned and it contains a high-confidence template-injection finding; these are meaningful workflow hygiene risks.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
twig/twig Version ^3.14 | — | — |
composer/composer Version >=2.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.