Package Health

wol-soft/twig-include-dir

The linked project was pushed in August 2025, but has no commits in the last three months and no security policy. It includes tests, a README, and a matching repository, while workflow dependencies are unpinned.

Latest 2.1.0PackagistPackagist

61%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

50

Dependencies
Dependencies
Evaluates the health and security of package dependencies

100

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

88

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

67

Health Score Breakdown

Release historycaution

The package has had three releases since August 2018, but none in the last six years and the latest release was in December 2020. This is a meaningful maintenance concern despite the repository having a recent push.

Repo commit activitycaution

No commits and no active maintainers were observed in the last three months. Although the repository was pushed in August 2025, the current short-term activity still indicates limited ongoing maintenance.

Repo toolingcaution

The project uses Composer but has no detected security scanning tools. For a small package this is a hygiene gap, not evidence of abandonment by itself.

Security policycaution

The repository has no security policy. This reduces transparency for reporting and handling vulnerabilities, though it does not by itself make the package unfit.

Workflow auditcaution

The workflow audit completed successfully with no dangerous triggers, untrusted checkouts, script injection, or audit findings. However, both analyzed action references are unpinned, leaving a modest supply-chain hygiene gap.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

wol-soft

Direct Dependencies

DependencyLast ReleaseScore
twig/twig
Version >= 2.7 < 4.0
—
—

Weekly Downloads

Info

Last Published
5 years ago
Created
8 years ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform