A clear README, tests, MIT licensing, and a small dependency set make adoption straightforward. Dependabot and release notes addressing a security patch provide useful supporting evidence, but ongoing oversight is limited.
67%
Total Score
50
100
94
75
The package has existed since 2017 and has seven releases, but it has had no release in the last two years. That weakens confidence that maintenance will continue.
There were zero commits and zero active maintainers in the last three months. Combined with no registry release in two years, this indicates limited current maintenance.
The repository has no published security policy. For a small library this is a transparency gap, though the release notes do document a dependency security update.
The single workflow was fully analyzed with no dangerous triggers, sinks, or audit findings. However, both action references are unpinned, leaving the workflow exposed to upstream action changes.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
twig/twig Version ^3.4.3 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.