The package includes a substantial README, tests, an MIT license, and no install-time scripts. Its lack of security tooling and policy adds transparency concerns alongside the long maintenance gap.
58%
Total Score
50
100
78
83
The package has had only 2 releases, with none in the last 12 months; its latest release was about 9 years ago. This is strong evidence of stalled maintenance for a library dependency.
There were 0 commits and 0 active maintainers in the last 3 months, consistent with the repository's last push about 9 years ago. This materially raises abandonment risk.
There are no open issues or pull requests, and no issue or pull-request activity in the last month. With no recent commits, this is more consistent with inactivity than with demonstrably complete maintenance.
The repository has 6 stars and 2 forks, indicating limited adoption. Popularity is supporting evidence only and does not independently determine package health.
Composer and Phing build tooling are present, but no security-scanning tools were detected. The build setup is a positive, while the missing security tooling is a modest transparency gap.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
twig/twig Version ^1.2|~2.0 | — | — |
roave/security-advisories Version dev-master | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.