The package has strong documentation and licensing, with release notes for this version and a published security policy. Its broad dependency surface and install-time scripts increase maintenance and deployment complexity.
65%
Total Score
50
50
94
75
The release declares 44 runtime dependencies across a large CMS framework stack, creating substantial upgrade and transitive-maintenance exposure.
The package runs post-create, post-install, and post-update Composer scripts, increasing install-time behavior and operational complexity for consumers.
One contributor made all commits in the last 3 months, leaving maintenance dependent on a single active repository contributor.
Only 1 commit was recorded in the last 3 months, indicating limited recent repository activity despite the frequent registry releases.
Composer build tooling is present, but no repository security-scanning tools were detected, leaving a documented security-process gap.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
doctrine/orm Version ^2.6.3 | — | — |
se7enxweb/twig Version ^2.5 | — | — |
symfony/thanks Version ^1.1.0 | — | — |
scssphp/scssphp Version ~1.0 | — | — |
twig/extensions Version ^1.5.3 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.