The package has tests, a substantial README, matching MIT licensing, and an organization-backed repository. Its workflows use five unpinned actions, and no security policy or scanning tools are present.
68%
Total Score
83
100
83
67
The package is young, with three releases over 127 days and a median interval of about 7 days. This shows active initial delivery but provides limited long-term maintenance evidence.
The repository had zero commits and zero active maintainers in the last three months. For a package only about four months old, that is a meaningful warning about ongoing maintenance capacity.
The repository has four stars and no forks or watchers. This is limited adoption evidence, but popularity is supporting evidence and does not outweigh the package's other signals.
Composer build tooling is present, but no security scanning tools were detected. The missing scanning is a modest hygiene gap rather than evidence of abandonment.
The repository has no security policy. This reduces vulnerability-reporting transparency, although it is not by itself evidence that the package is unsafe.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
intervention/image Version ^4.0 | — | — |
intervention/image-laravel Version ^4.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.