Default Jimp plugin.
61%
Total Score
caution
Usable with caveats: no registry release in over two years and no repository commits in the last three months.
The package declares 22 runtime dependencies, mostly Jimp plugins, creating a broad coordinated dependency surface that can increase upgrade and maintenance risk.
The package has 222 releases since 2018, but its latest release was over two years ago and there were no releases in the last 12 months, indicating a meaningful maintenance slowdown.
No commits or active maintainers were recorded in the last three months, which weakens evidence of ongoing maintenance despite the repository not being archived.
The repository has no security policy, leaving vulnerability reporting and response expectations less transparent.
Both analyzed workflows grant top-level write permissions and all 8 action references are unpinned. There are no untrusted checkouts, script injections, or reported high-severity findings, so this is a hygiene concern rather than a severe risk.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
timm Version ^1.6.1 | — | — |
@jimp/plugin-blit Version ^0.22.12 | — | — |
@jimp/plugin-blur Version ^0.22.12 | — | — |
@jimp/plugin-crop Version ^0.22.12 | — | — |
@jimp/plugin-flip Version ^0.22.12 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.