Clear licensing, organization backing, and a repository that matches the package support adoption. Its metapackage layout is appropriate, but the release has not yet built a maintenance track record.
76%
Total Score
75
100
88
75
This package was first released today and has only one release, so there is no meaningful release or maintenance history yet. Its immediate publication date partly explains the gap but does not remove the limited track record.
There were no commits or active maintainers in the preceding three months, but the repository was created or updated today and the package has only just been released. This leaves maintenance capacity unproven rather than demonstrating a collapsed project.
The repository uses Composer for its build, which fits the package ecosystem, but no security-scanning tool was detected. For this small metapackage that is a modest transparency gap, not a severe concern.
The repository has no security policy. That limits published security-response guidance, although the package is a small type-definition metapackage.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
tyhpdef/twig-twig-impl Version ~3.28.0.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.