Documentation is adequate, and the project has a clearly matching source repository. Its one-person maintenance base, absent security policy, install-time script, and long gap in registry releases warrant caution before adoption.
58%
Total Score
67
81
67
Only three releases exist, with the latest registry release on January 28, 2018 and none in the last 12 months. This is a substantial release-maintenance concern, despite recent repository activity.
The package runs a post-install command, adding install-time execution that consumers should understand before depending on the release.
The package and repository are owned by the same individual account, providing clear ownership but no organizational backing to broaden maintenance capacity.
All five recent commits came from one contributor, leaving maintenance dependent on a single person.
Composer is used for builds, but no security-scanning tooling was detected, leaving a modest transparency and assurance gap.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
twig/twig Version ^2.1 | — | — |
symfony/yaml Version ^3.2 | — | — |
symfony/http-foundation Version ^3.2 | — | — |
villermen/data-handling Version ^1.14 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.