Tests, a matching README, a license, and security scanning provide useful project support. Only one contributor made one commit in the last three months, and no security policy is published.
60%
Total Score
50
94
50
The package has had no registry releases in the last 12 months, and its latest release was in January 2021. The recent repository push provides some evidence of continued project activity, but does not remove release staleness.
All one recent commit came from a single contributor, leaving maintenance dependent on one active person. The package is user-owned rather than organization-owned, so there is no provided organizational backing to offset this concentration.
Only one commit was recorded in the last three months, indicating limited recent development activity despite the repository remaining active.
The repository has no published security policy, reducing transparency about vulnerability reporting and response.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
twig/twig Version ~2.7 || ^3 | — | — |
voku/html-min Version ~4.4 | — | — |
voku/simple-cache Version ~4.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.