It has a clear MIT license, tests, README, and no install scripts or deprecation. The organization-backed repository matches the package, but it has no security policy or scanning.
65%
Total Score
67
100
81
75
The package is only 160 days old and published 18 releases, mostly within a seven-day burst; its latest release was about five months ago, leaving limited evidence of sustained maintenance.
All recent commit activity comes from one contributor. Organization ownership provides some handoff capacity, but no second active contributor is shown.
Only one commit was recorded in the last three months, indicating weak recent maintenance activity despite the repository remaining available.
Composer build tooling is present, but no security-scanning tool was detected, leaving a modest transparency and maintenance gap.
The repository has no security policy, so its reporting and response expectations are not documented.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
twig/twig Version ^3.0 | — | — |
preflow/view Version ^0.1 || @dev | — | — |
preflow/components Version ^0.1 || @dev | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.