The package offers almost no consumer documentation, and its 24 runtime dependencies increase upgrade and compatibility burden. Its repository is not archived and has Composer tooling, but release and commit activity has been absent for several years; pinning this version is prudent.
52%
Total Score
50
50
75
75
The package declares 24 runtime dependencies and no development dependencies, creating a comparatively large compatibility and maintenance surface for a small 24-file package.
The artifact includes a README, but it is only 34 characters and says “It doesn't...”, offering essentially no integration guidance. Missing tests and changelog files are normal for published artifacts and do not add concern here.
The package has only 5 releases, with none in the last 12 months; the latest registry release was on October 23, 2022. This indicates a substantial maintenance gap for a library dependency.
There were 0 commits and 0 active maintainers in the last 3 months, consistent with the long release gap. This raises abandonment risk, although the repository is not archived.
The linked repository has no security policy. This is a transparency gap, though the absence is a secondary concern compared with the lack of recent maintenance evidence.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
cocur/slugify Version ^3.2 | — | — |
guzzlehttp/guzzle Version ^7 | — | — |
cita/image-cropper Version ^2.0.3 | — | — |
bummzack/sortablefile Version ^2.0 | — | — |
silverstripe/tagfield Version ^2.4 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.