The source repository is still present and matches the package, with documentation and a changelog available. However, the license text does not match the manifest declaration, and current maintenance or security support is not evident.
20%
Total Score
0
58
Packagist marks the entire package as abandoned, with no replacement provided. This is a severe adoption risk because the registry explicitly signals that dependents should not expect continued support.
The package has 12 releases since August 2014 but none in the last six years, with the latest release in May 2020. That long release gap strongly indicates abandonment for a library that may need compatibility and security fixes.
The repository has no commits and no active maintainers in the last three months. Although the repository was pushed in July 2023, the recent activity data does not show ongoing development capacity.
A license file is present, so this is not an unlicensed release, but it is identified as BSD-2-Clause while the manifest declares BSD-3-Clause. The mismatch creates avoidable legal uncertainty for adopters.
| Title | Versions | Severity |
|---|---|---|
CVE-2017-14077 dapphp/securimage is vulnerable to Improper Control of Generation of Code ('Code Injection') in versions 0.0.0 - 3.6.6. | 0.0.0 - 3.6.6 | Medium |
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.