It has clear MIT licensing, tests, a readable package layout, and a working Composer build. Limited public adoption and missing security practices reduce confidence in long-term support.
64%
Total Score
50
89
75
There were no commits and no active maintainers in the last three months. The recent push and release provide some compensating evidence, but the current maintenance gap still lowers confidence.
The repository has zero stars, forks, and watchers, so there is little public evidence of adoption or community support; popularity is supporting evidence, not a verdict.
Composer build tooling is present, but no security scanning tools were detected, leaving a modest transparency and maintenance gap.
The repository has no security policy, making vulnerability reporting and response expectations less clear.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
jcupitt/vips Version ^2.6 | — | — |
spatie/image Version ^3.0 | — | — |
coco-project/logger Version ^1.0 | — | — |
php-ffmpeg/php-ffmpeg Version ^1.3 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.