The repository includes tests, a useful README, and a small dependency set. It has had no releases or commits since 2018, and the project has no security policy or scanning.
58%
Total Score
50
100
71
83
The package has 12 releases, but none in the last 12 months and the latest release was about eight years ago. This is strong evidence of abandonment risk, though the repository is not archived or deprecated.
There were zero commits and zero active maintainers in the last three months, consistent with no meaningful repository activity since 2018. This materially raises the risk that defects or compatibility issues will remain unresolved.
Composer is used for builds, but no security-scanning tool was detected. The missing scan reduces maintenance transparency, although it is less significant than the long-term inactivity.
The repository has no security policy. For an image-processing library, that leaves vulnerability reporting and response expectations unclear.
Version 0.5.3 is a stable, non-prerelease release, but the package has not reached a stable major version. This is a modest maturity concern rather than a release-quality failure.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
imagine/imagine Version 0.7.* | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.