The small dependency surface, tested codebase, and MIT declaration improve transparency and reduce integration risk. A security policy is absent, and the repository has very little community activity, so future fixes and support are uncertain.
42%
Total Score
67
100
78
75
The package has had no release in over seven years, despite nine releases in its early history; this is strong evidence of abandonment risk.
There were zero commits and zero active maintainers in the last three months, consistent with the multi-year release gap and increasing abandonment risk.
There were no recent issues or pull requests, which is consistent with a dormant project but is weaker evidence than the absent release and commit activity.
The repository has two stars and one fork, indicating limited external adoption and a small community available to notice or fix problems.
Composer is used for builds, but no security scanning tools are present; this is a modest transparency and maintenance gap rather than a severe risk.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
twig/twig Version ^1.23 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.