It includes tests, release notes, a license, and a security policy. The six workflow actions are unpinned, and recent commit activity is currently quiet.
78%
Total Score
83
100
94
75
There were zero commits and zero active maintainers in the last three months. The recent release partly offsets this, but ongoing maintenance activity is currently quiet.
Composer is used for the build, but no security-scanning tools were detected. The repository's security policy and workflow audit provide some compensating transparency.
Both workflows were fully analyzed with no dangerous triggers, untrusted checkouts, script injection, or audit findings. However, all six action references are unpinned, leaving avoidable supply-chain drift risk.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
twig/twig Version ^3.3 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.