The package has solid consumer-facing documentation and basic project discipline, with no install-time scripts. Its solo-maintainer base and lack of a security policy leave some continuity and disclosure risk.
76%
Total Score
50
94
75
One contributor made all commits during the last three months, leaving maintenance highly dependent on a single individual.
Only one commit was recorded in the last three months, which is limited activity, although the recent release history provides some compensating evidence.
The project uses Composer for builds, but no security-scanning tooling was detected; this is a modest transparency and maintenance gap.
No repository security policy was found, leaving vulnerability reporting and disclosure expectations unclear.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
twig/twig Version ^2.12|^3.0 | — | — |
symfony/form Version ^6.4|^7.0|^8.0 | — | — |
google/recaptcha Version ^1.3 | — | — |
symfony/validator Version ^6.4|^7.0|^8.0 | — | — |
twig/extra-bundle Version ^2.12|^3.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.