Healthy and usable for production, with some repository-security caveats. It has a long release history, a stable current version, active organizational backing, and a recent release, but the repository had no commits in the last three months and lacks a security policy.
78%
Total Score
75
100
94
50
One workflow uses pull_request_target, which requires careful handling of untrusted pull requests, although no untrusted checkout or script injection was detected in the analyzed workflows.
The repository recorded zero commits and zero active maintainers in the last three months, which weakens confidence in ongoing maintenance despite the May 2026 push and the recent 4.11.0 release.
There are no open issues and one open pull request, but no issues or pull requests were merged in the last month. This is a small caution about current throughput, not strong abandonment evidence by itself.
The repository uses Composer and Make and has seven workflows, but no security-scanning tooling was detected. This is a transparency and process gap rather than evidence that the package is unsafe.
No repository security policy was found, leaving vulnerability-reporting and response expectations undocumented.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
twig/twig Version ^3.0 | — | — |
symfony/form Version ^6.4 || ^7.3 || ^8.0 | — | — |
cocur/slugify Version ^4.0 | — | — |
symfony/config Version ^6.4 || ^7.3 || ^8.0 | — | — |
symfony/console Version ^6.4 || ^7.3 || ^8.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.