The repository includes tests, a changelog, clear usage documentation, and MIT licensing. Install and update hooks add some operational risk, while the workflow audit found no dangerous patterns but did find unpinned actions.
45%
Total Score
63
100
72
50
Only two releases were published, with the latest on July 14, 2016 and none in the last 12 months. This long release gap is strong evidence of abandonment risk.
There were no commits or active maintainers in the preceding three months. Combined with the last registry release in 2016, this materially raises abandonment risk.
The package runs post-install and post-update Composer hooks. These scripts deserve caution because they execute during dependency operations, although this signal alone does not establish a severe risk.
There are no open issues or pull requests and no activity in the last month. This is consistent with a quiet project but does not independently show whether maintenance needs are being handled.
The repository has 7 stars and 3 forks. This is limited adoption evidence, but popularity is supporting context and does not outweigh the direct maintenance signals.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
twig/twig Version ^1.17|^2.0@dev | — | — |
league/commonmark Version ^0.13.2|^0.14 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.