Regular releases, recent commits, stable versioning, and an MIT license support continued use. The small audience and limited security documentation leave more maintenance risk than a mature project.
64%
Total Score
63
100
83
75
Only one registry account has publishing access. The linked repository is also user-owned rather than organization-owned, so there is little visible publishing redundancy.
The package has no README, tests, or changelog, although the repository uses GitHub releases and this exact version has a GitHub release. The missing README reduces consumer guidance for a framework-style library.
The repository owner is an individual account, not an organization, which provides no visible organizational handoff capacity to offset the concentrated maintainer base.
All 8 recent commits came from one contributor, giving the project a high maintenance concentration with no second active contributor to provide continuity.
The repository has zero stars and forks and only one watcher. Popularity is not decisive, but this provides little independent evidence of broad adoption or review.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
twig/twig Version ^v3.19.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.