The MIT license and small dependency footprint make the release straightforward to inspect and install. The project has had no commits or releases for over five years, with one visible maintainer and no security policy or scanning.
44%
Total Score
25
100
71
50
This is the package's only release, published over five years ago, with no releases in the last 12 months. That is strong evidence of abandonment risk, although the repository is not archived.
There were no commits and no active maintainers in the last three months. Combined with the old release history, this materially increases abandonment risk.
The registry has one maintainer account, and the backing repository is owned by an individual rather than an organization. This leaves limited visible maintenance capacity if that person stops working on it.
Composer build tooling is present, but no security scanning tools were detected. This is a modest hygiene gap rather than evidence that the release is unsafe.
The repository has no security policy. For a small image-synthesis tool this is not severe alone, but it reduces transparency for reporting and handling vulnerabilities.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.