Integration should be straightforward, with clear licensing, tests, and no install-time scripts. Security coverage is limited because the repository has no security policy or scanning tools.
62%
Total Score
50
100
88
83
Only one registry account can publish the package, creating a thin publishing base; the matching user-owned repository provides some continuity but not redundancy.
There were zero commits and zero active maintainers in the last three months. The recent release and repository push show some activity, but ongoing maintenance appears quiet.
Composer is used for builds, but no security scanning tools are configured, leaving less automated protection for dependency and repository changes.
The repository has no security policy, so users lack a documented channel and process for reporting vulnerabilities.
Version 0.3.2 is not a prerelease, but the pre-1.0 major version signals less maturity than a stable-major release.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
twig/twig Version * | — | — |
tomk79/filesystem Version ^1.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.