Usable with caveats: the release is active, documented, tested in the repository, and not deprecated or archived. Adoption depends heavily on one contributor, while the repository lacks security scanning and a security policy and has permissive workflow settings that merit review.
68%
Total Score
50
100
89
80
The registry namespace and repository owner match, but the owner is a user account rather than an organization, so there is no organizational backing to offset the concentrated maintainer base.
One contributor made 100% of the four recent commits, creating a substantial single-person continuity risk; the repository owner is an individual rather than an organization.
Four commits in the last 3 months show recent activity, but all activity comes from one active maintainer, limiting evidence of sustained maintenance capacity.
There are no open issues or pull requests and no recent issue or pull-request activity. That may indicate a quiet project, but it provides little independent evidence of community maintenance.
The repository has zero stars, forks, and watchers. This is supporting evidence of limited external adoption, not by itself evidence that the package is unsafe to use.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
craftcms/cms Version ^5.0.0 | — | — |
srwiez/thumbhash Version ^1.5 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.