The package includes substantial documentation, tests, and a matching organization-owned repository. Its workflow uses three unpinned actions, and the project has not established security scanning or a security policy. Maintenance is still unproven because this is the first published release.
65%
Total Score
75
80
67
This is the first release, published 0 days ago, so there is no release cadence or history demonstrating sustained maintenance. Its very recent publication limits how strongly the absence of history should be penalized.
There were 0 commits and 0 active maintainers in the last 3 months. Because the repository and package were created only today, this is mainly a lack of evidence for ongoing maintenance rather than evidence of abandonment.
The linked repository has no security policy, leaving vulnerability-reporting expectations undocumented. This is a transparency and maintenance gap, though it does not by itself make the release unfit.
Version v0.1.0 is an early, non-stable-major release, which signals API and maintenance maturity are not yet established. It is not marked as a prerelease, providing a small counterweight.
The single workflow was fully analyzed, uses read-only permissions, and has no dangerous triggers or audit findings. However, all 3 of its 3 action references are unpinned, leaving the build exposed to reference changes.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
twig/twig Version ^3.12 | — | — |
symfony/asset Version ^7.3 || ^8.0 | — | — |
symfony/config Version ^7.3 || ^8.0 | — | — |
symfony/http-kernel Version ^7.3 || ^8.0 | — | — |
symfony/twig-bundle Version ^7.3 || ^8.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.