The repository has no security policy or automated security-scanning tooling, while its single registry maintainer and zero stars provide little visible support. The stable, non-deprecated release still carries substantial maintenance and transparency risk.
35%
Total Score
50
71
50
Neither the package metadata nor the artifact or repository contains a recognized license, leaving the terms for using and redistributing this dependency unclear.
The package has had no releases in the last 12 months, and its latest release was on December 28, 2023, indicating prolonged inactivity for a package consumers may depend on.
The repository recorded zero commits and zero active maintainers in the last three months, providing no recent evidence of maintenance capacity.
The repository name does not match the package name and its README does not mention the package, so the linked source may not clearly establish ownership of this release.
Composer build tooling is present, but no security-scanning tools are reported, limiting evidence that dependency or code risks are checked automatically.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
intervention/image Version ^2.5 | — | — |
unisharp/laravel-filemanager Version ^2.2 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.