A README, tests, and an organization-owned repository provide useful maintenance context. The extra BSD-2-Clause license evidence and lack of repository security tooling leave some transparency gaps.
45%
Total Score
50
72
83
The latest release was nearly four years ago, with no releases in the last 12 months. This is strong evidence that maintenance has stopped, although the package has 11 releases overall.
The repository had zero commits and zero active maintainers in the last three months, consistent with the long release gap. That substantially increases abandonment risk.
The artifact declares MIT and includes license files, so the release is licensed. The detected files also include BSD-2-Clause beyond the declaration, creating a licensing clarification gap.
The repository has 0 stars, 0 forks, and 1 watcher. Popularity is only supporting evidence, but these figures provide little indication of a broader maintenance community.
Composer build tooling is present, but no security-scanning tool was detected. That is a modest hygiene gap alongside the observed maintenance slowdown.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
intervention/image Version ^2.7 | — | — |
php-ffmpeg/php-ffmpeg Version dev-master | — | — |
laravel/legacy-factories Version ^1.1 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.