The stable major version, matched source repository, and organization backing provide useful continuity. The small project has limited process visibility, with no security policy and minimal consumer documentation.
62%
Total Score
75
81
50
A README is present, but it is only 25 characters and the package and repository contain no tests or changelog. The absence of tests and a changelog is normal packaging practice; the very limited README modestly reduces transparency.
The package has 15 releases since December 2019, but none in the last 12 months; the latest release was about 18 months ago. This suggests maintenance has slowed, though the release history is established rather than abandoned.
There were no commits and no active maintainers in the last three months, consistent with the lack of releases for about 18 months. This is a meaningful maintenance concern, but the repository is not archived.
The repository uses Composer, providing ordinary build tooling, but has no security scanning configured. The missing scanning is a modest hygiene gap rather than evidence of abandonment.
The repository has no security policy, which leaves vulnerability reporting and response expectations undocumented.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
twig/twig Version ^3.5 | — | — |
monolyth/envy Version ^0.7.6 | — | — |
monolyth/frontal Version ^1.1.4 | — | — |
monolyth/improse Version ^0.7.4 | — | — |
monolyth/disclosure Version ^3.2 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.