Documentation and licensing are in place, and the repository is backed by an organization with a matching package. Maintenance has paused since February 2025, with no commits or issue movement in the measured periods; the missing security policy adds a smaller transparency concern.
58%
Total Score
67
86
67
The package has 18 releases over more than 11 years, but none in the last 12 months; its latest release was in February 2025. This indicates a mature but currently inactive release cadence.
The repository recorded zero commits and zero active maintainers over the last three months. Combined with the February 2025 last push, this is a meaningful abandonment risk.
There were no new or closed issues and no merged pull requests in the last month, while 13 issues and 3 pull requests remain open. This shows little current project movement.
Composer is used as the build tool, but no security scanning tooling is present. The missing scanning is a modest hygiene gap rather than evidence that the release is unsafe.
The repository has no published security policy. For a package that processes application assets, this reduces transparency about reporting and handling vulnerabilities.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
natxet/cssmin Version 3.* | — | — |
tedivm/jshrink Version ~1.0 | — | — |
illuminate/support Version ^10.0|^11.0|^12.0 | — | — |
illuminate/filesystem Version ^10.0|^11.0|^12.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.