The repository includes tests and the release has notes, but there has been no registry release in about 22 months and no commit activity in the last 3 months. A single publisher and missing security scanning add maintenance risk, while the project remains licensed and unarchived.
65%
Total Score
50
100
89
50
One registry maintainer is consistent with the repository being user-owned, but it leaves the publishing path dependent on a single person.
The package has four releases over about 3 years and none in the last 12 months; the latest release was about 22 months ago, indicating slow maintenance.
The repository recorded zero commits and zero active maintainers in the last 3 months, reinforcing the concern from the absence of recent registry releases.
Composer build tooling is present, but no security scanning tools were detected, leaving a modest transparency and maintenance gap.
No security policy was found in the repository, reducing the clarity of the process for reporting and handling security issues.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
twig/twig Version ^3.15 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.