The project has strong documentation, repository tests, and an active recent release history. Its pre-1.0 status, very small public footprint, and three unpinned workflow actions leave moderate maturity and build-hygiene concerns.
78%
Total Score
83
100
83
88
Only one registry account publishes the package, but the repository is owned by an organization, making this a modest publishing-capacity concern rather than evidence of abandonment.
Three stars and no forks or watchers indicate a very small public user and contributor footprint, which limits external maintenance evidence but does not outweigh the observed project activity.
Composer build tooling is present, but no repository security scanning tools were detected, leaving a moderate security-process gap.
v0.3.1 is not a stable major release, so API compatibility may still change even though it is not marked prerelease.
The only workflow was fully analyzed with no detected dangerous sinks or audit findings, and it scopes permissions at job level. However, all 3 of 3 action references are unpinned, leaving avoidable workflow supply-chain hygiene risk.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
twig/twig Version ^3.0 | — | — |
symfony/yaml Version ^6.4||^7.0||^8.0 | — | — |
symfony/config Version ^6.4||^7.0||^8.0 | — | — |
symfony/http-kernel Version ^6.4||^7.0||^8.0 | — | — |
symfony/twig-bundle Version ^6.4||^7.0||^8.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.