The package includes tests, a clear AGPL license, and no install-time scripts. Its one-person, inactive repository and absent security policy make long-term maintenance and support uncertain.
42%
Total Score
25
100
69
75
The package has had no release in about 4 years and 7 months, with only three releases overall and none in the last 12 months. This is strong evidence of abandonment for a dependency that may need compatibility updates.
There were zero commits and zero active maintainers in the last three months, consistent with no development since February 2022. This substantially increases abandonment and compatibility risk.
Only one registry account has publish access. That is a limited publishing base, and the repository owner is an individual rather than an organization, so there is little visible redundancy if the maintainer stops supporting the package.
The repository has zero stars, forks, and watchers. Popularity is not required for a healthy small package, but these counters provide no supporting evidence of an active user or contributor community.
Composer build tooling is present, but no security scanning tools are configured. For a package that runs an external OCR command, the missing security checks reduce transparency around ongoing maintenance.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.