Its compact package includes a README, repository tests, a changelog, and a security policy. The long pause in releases and commits, plus an unpinned container image in CI, make this old alpha release a risky choice for a new dependency.
42%
Total Score
50
79
100
The latest release was published in February 2022, with no releases in the last 12 months. This extended release gap is strong evidence of abandonment risk despite a previously regular cadence.
The repository recorded zero commits and zero active maintainers during the last three months. Combined with the old latest release, this indicates a substantial maintenance gap.
Version 0.1.1 is below a stable 1.0 release, so compatibility expectations are limited. The release is not marked as a prerelease, which provides only modest compensation.
All three workflows were analyzed and no untrusted checkout or script-injection path was found, but the audit identified a high-confidence unpinned container image and all seven action references are unpinned. This is a meaningful CI supply-chain hygiene weakness, though not severe enough on its own to make the package unfit.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
intervention/image Version ^2.5 | — | — |
kornrunner/blurhash Version ^1.2 | — | — |
illuminate/contracts Version ^9.0 | — | — |
spatie/laravel-package-tools Version ^1.4.3 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.