The package includes a README, tests, and a changelog, while organization ownership and a small runtime dependency set provide useful support. Its maintenance and security visibility are limited.
55%
Total Score
50
100
64
50
The latest release was published in June 2018, about 8 years ago, and there have been no releases in the last 12 months. This is strong evidence of a stale release line, though the package has a multi-year release history.
There were no commits or active maintainers in the last 3 months. Combined with the last push being years ago, this materially raises abandonment risk.
Composer is used for builds, but no security-scanning tool was detected. That limits automated security visibility, while the package's small runtime dependency set reduces the practical impact.
The repository is not archived, but it was last pushed in June 2019, indicating that it remains available without showing recent maintenance.
The repository has no security policy. This is a transparency and reporting gap, although it is less significant for a small, old template-oriented package than for security-sensitive infrastructure.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.