Its long release history, stable major version, organization backing, tests, and release notes support continued use. Missing security policy and unpinned workflow actions leave maintenance and build-reproducibility gaps.
68%
Total Score
75
93
50
The package is mature, with 104 releases over more than 12 years and a release as recent as February 2026, but only one release in the last 12 months suggests a slower current cadence.
No commits or active maintainers were recorded in the last three months. The recent release partly offsets this, but the absence of current development activity remains a maintenance concern.
No repository security policy was found, leaving vulnerability-reporting expectations and response procedures undocumented.
Both workflows were fully analyzed with no high-confidence findings or dangerous triggers, but all 8 action references are unpinned, weakening build reproducibility and update control.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
phug/phug Version ^1.6 || ^2.0.0 | — | — |
js-phpize/js-phpize-phug Version ^1.1 || ^2.0 | — | — |
phug/js-transformer-filter Version ^1.0 | — | — |
nodejs-php-fallback/nodejs-php-fallback Version ^1.3.1 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.