It has a clear license, a matching repository, and release notes for version 2.0.0. The limited release cadence and absent security policy leave less evidence of ongoing maintenance and security practice.
68%
Total Score
100
100
93
75
The package has only 3 releases over about 2 years and none in the past 12 months; the latest release was on September 20, 2025. This indicates a slow cadence, though the recent 2.0.0 release provides some evidence of continued maintenance.
The repository has no security policy, leaving no documented process for reporting or handling vulnerabilities in a package that processes user-supplied SVG content.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
meyfa/php-svg Version ^0.16.1 | — | — |
enshrined/svg-sanitize Version ^0.22.0 | — | — |
silverstripe/framework Version ^6.0.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.