The repository has basic build and security tooling, a matching package name, and organization backing. Its short history and single active contributor leave limited evidence of long-term stability; pin this version while adoption remains limited.
65%
Total Score
67
94
83
The package is only 43 days old, with 110 releases published on the same day and a median release interval of 0 days. That shows active initial publishing but provides little evidence of a settled release process.
One contributor made all 2 commits in the last 3 months. Organization ownership provides some handoff capacity, but no second active contributor is shown.
Only 2 commits were recorded in the last 3 months, indicating a very small recent maintenance footprint. Recent repository activity partly offsets this, but it does not establish a durable cadence.
No repository security policy was found. This is a minor transparency gap, especially for a package intended to be integrated into applications.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
twig/twig Version ^3.4|^4.0 | — | — |
symfony/config Version ^8.1 | — | — |
survos/kit-bundle Version ^2.5 | — | — |
symfony/dependency-injection Version ^8.1 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.