Clear licensing, repository tests, and release notes provide good transparency. The alpha status and concentration of recent commits in one contributor warrant pinning and watching future releases.
72%
Total Score
88
100
89
100
Recent activity is concentrated: one contributor made five of six commits. A second contributor remains active and organization backing partly compensates, but handoff risk is still present.
Composer build tooling is present, but no repository security-scanning tool was detected; this is a modest transparency and maintenance gap rather than evidence of unfitness.
This release is v4.0.0-alpha1 while the latest stable version is v3.26.0, so it carries pre-release compatibility risk despite the project's generally low recent prerelease share.
| Title | Versions | Severity |
|---|---|---|
CVE-2026-46629 twig/intl-extra is vulnerable to Allocation of Resources Without Limits or Throttling in versions 0.0.0 - 3.26.0. | 0.0.0 - 3.26.0 | Low |
| Dependency | Last Release | Score |
|---|---|---|
twig/twig Version ^3.13|^4.0 | — | — |
symfony/intl Version ^5.4|^6.4|^7.0|^8.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.