The source is easy to inspect, with a README, release notes, and no install-time scripts. Single-user ownership, no recent commits, and the license mismatch leave limited evidence of dependable ongoing support.
58%
Total Score
50
80
75
The manifest declares MIT, but the artifact and repository license file are detected as GPL-3.0. The release is licensed, but the disagreement creates a material adoption and compliance concern.
Only one registry publishing maintainer is listed, and project backing identifies a personal account rather than an organization. This leaves a thin apparent support base when combined with the lack of recent commits.
This is the only release, published 281 days ago, with no subsequent release activity. That is limited evidence of project maturity or continued maintenance.
The repository recorded zero commits and zero active maintainers in the last 3 months, despite being a relatively new project. No stronger maintenance signal compensates for that inactivity.
The repository has no security policy, reducing transparency for reporting and handling vulnerabilities. This is a hygiene gap rather than evidence that the package is unsafe.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
twig/twig Version ^3.13|^4.0 | — | — |
symfony/string Version ^5.4|^6.4|^7.0 | — | — |
symfony/translation-contracts Version ^1.1|^2|^3 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.