It is clearly licensed, has a useful README, and includes release notes and repository tests. The workflow audit found no unsafe trigger or injection pattern, though all nine action references are unpinned.
12%
Total Score
0
50
50
Packagist marks the entire package as abandoned, with no replacement package provided. This is a severe warning against taking a new dependency on the release.
The package has had no releases in the last 12 months, despite a median release interval of about 23 days previously. This supports the evidence of a stopped project.
The repository recorded zero commits and zero active maintainers in the last three months. Together with the archived status, this indicates no ongoing maintenance capacity.
The linked repository is archived, and its last push was on June 25, 2024. An archived source project is a severe abandonment risk.
The repository has no security policy. This reduces transparency and gives consumers no documented reporting process, though it is secondary to the abandonment signals.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
meyfa/php-svg Version ^0.15.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.