The license, tests, and source layout make integration clearer. The workflow is complete but uses two unpinned actions, and no security policy is provided; pin v1.1.0 only after confirming ongoing maintenance.
55%
Total Score
50
92
67
The package is less than one day old with only two releases, so there is not enough history to establish reliable maintenance or long-term support.
The repository has zero commits and zero active maintainers in the past three months. Because the release is newly published, this is mainly an unproven-maintenance concern rather than evidence of abandonment.
The repository has no security policy, which reduces transparency for reporting vulnerabilities in a package that handles uploaded media and permissions.
The single workflow was fully analyzed with no dangerous triggers or audit findings, but both of its two action references are unpinned, leaving avoidable build-integrity exposure.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
illuminate/http Version ^8.0 || ^9.0 || ^10.0 || ^11.0 | — | — |
illuminate/view Version ^8.0 || ^9.0 || ^10.0 || ^11.0 | — | — |
illuminate/routing Version ^8.0 || ^9.0 || ^10.0 || ^11.0 | — | — |
illuminate/support Version ^8.0 || ^9.0 || ^10.0 || ^11.0 | — | — |
intervention/image Version ^2.7 || ^3.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.