The linked project was pushed in August 2025, but has no commits in the last three months and no security policy. It includes tests, a README, and a matching repository, while workflow dependencies are unpinned.
61%
Total Score
50
100
88
67
The package has had three releases since August 2018, but none in the last six years and the latest release was in December 2020. This is a meaningful maintenance concern despite the repository having a recent push.
No commits and no active maintainers were observed in the last three months. Although the repository was pushed in August 2025, the current short-term activity still indicates limited ongoing maintenance.
The project uses Composer but has no detected security scanning tools. For a small package this is a hygiene gap, not evidence of abandonment by itself.
The repository has no security policy. This reduces transparency for reporting and handling vulnerabilities, though it does not by itself make the package unfit.
The workflow audit completed successfully with no dangerous triggers, untrusted checkouts, script injection, or audit findings. However, both analyzed action references are unpinned, leaving a modest supply-chain hygiene gap.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
twig/twig Version >= 2.7 < 4.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.