The repository is intact, clearly matches the package, and includes a useful README, tests, and a stable MIT license. The single publisher and zero commits in the last three months reduce confidence in ongoing maintenance, while the absent security policy is a smaller transparency gap.
64%
Total Score
75
100
88
83
The package has existed since 2016 with 11 releases, but it had no releases in the last 12 months; the latest release was about 14 months ago. This indicates low current release momentum, though the long history provides some maturity evidence.
There were zero commits and zero active maintainers in the last three months. This is the clearest sign of currently limited maintenance capacity, even though the repository was recently updated for the assessed release.
The repository uses Composer, but no security scanning tool was detected. Build tooling is present; the missing scanner is a modest security-maintenance gap rather than evidence of abandonment.
The repository has no security policy. This weakens vulnerability-reporting transparency, but it is a smaller concern than the lack of recent commit activity.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
twig/twig Version ^1.35||^2.12||^3.11 | — | — |
broccoli-html-editor/kaleflower Version ~0.2 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.