The package has clear usage documentation, an MIT license, and no install-time scripts. Its lack of tests, security scanning, and recent development limits confidence for a long-term dependency.
58%
Total Score
50
78
75
The latest release was in January 2022, around 4 years and 8 months ago, with no releases in the last 12 months. The package had a reasonable earlier cadence, but the prolonged pause raises abandonment risk.
The repository recorded no commits and no active maintainers in the last 3 months, consistent with the last push occurring in January 2022. This is a meaningful maintenance and abandonment concern.
The repository has no stars or forks and only one watcher, providing little external evidence of adoption or review. Popularity is supporting evidence, so this modestly lowers confidence rather than deciding the result.
Composer is used for the build, but no security scanning tool is configured. That is a hygiene gap rather than evidence that the package is unsafe.
The linked repository has no security policy, reducing transparency around vulnerability reporting and response. This matters more for a package that handles uploaded data, although it is not severe on its own.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
intervention/image Version ^2.7 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.