Clear documentation and a tested source tree help with adoption. The project is only 42 days old, with one commit from one contributor in the last three months; security scanning and a security policy are also absent.
67%
Total Score
50
100
88
83
The repository is owned by an individual user rather than an organization, so the concentrated maintainer activity is not offset by visible organizational backing.
The package is only 42 days old and has two releases, with a 42-day median interval. This is limited evidence of long-term maintenance, though the latest release was published recently.
One contributor made 100% of the recent commits. This concentrates maintenance knowledge and creates a meaningful continuity risk for a young package.
Only one commit and one active maintainer were observed in the last three months. The recent push is positive, but the activity base is too thin to demonstrate durable maintenance.
Composer build tooling is present, but no security scanning tools were detected. That is a transparency and hygiene gap rather than evidence that the package is unsafe.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
ipiner/pin Version ^1.0 | — | — |
intervention/image Version ^3.11 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.