A very rapid release stream suggests automated publishing, while the repository shows no commits or active maintainers in the last three months. Licensing, documentation, security scanning, and repository alignment are solid, but workflow permissions and unpinned actions add modest maintenance risk.
62%
Total Score
25
83
67
The repository recorded zero commits and zero active maintainers during the last three months. Combined with the unusually rapid release history, this weakens confidence in current maintenance capacity.
The package defines post-install and post-update Composer scripts. Install-time scripts increase dependency-installation complexity and deserve review, though this signal alone does not show harmful behavior.
The registry namespace and repository are owned by the same individual account, so the package has direct ownership alignment but no organization backing shown by this signal.
The package has made 70 releases in 288 days, with a median interval of about 15 minutes. This shows sustained publishing but is unusually automated and provides limited evidence that each release reflects meaningful maintenance.
The repository has six stars and no forks or watchers. Low popularity is not itself a health failure, but it provides little community evidence to offset the lack of recent commits.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
symfony/twig-bundle Version ^5.4|^6.0|^7.0|^8.0.4 | — | — |
symfony/options-resolver Version ^5.4|^6.0|^7.0|^8.0 | — | — |
symfony/ux-twig-component Version ^2.33 | — | — |
vardumper/extended-htmldocument Version ^0.2.82 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.