It has a clear MIT license and a usable README, but no security scanning is reported. The small repository has little adoption and no recent maintenance evidence, making future compatibility difficult to verify.
40%
Total Score
50
64
50
This is the package's only release, published nearly 10 years ago, with no releases in the last 12 months. That is strong evidence of abandonment risk, although the package is not marked deprecated.
The repository recorded zero commits and zero active maintainers in the last 3 months, consistent with the long release gap and leaving current maintenance capacity un demonstrated.
The repository has 0 stars and 0 forks, with only 1 watcher. Popularity is supporting evidence rather than a verdict, but these figures provide no meaningful external adoption signal.
Composer is used for the build, which is appropriate, but no security scanning tools are reported. This is a modest transparency and maintenance gap rather than a standalone severe risk.
The linked repository is not archived, so it remains available for inspection. Its last push was in August 2016, which limits the practical reassurance this status provides.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
cakephp/cakephp Version ~3.1 | — | — |
intervention/image Version ^2.3 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.