Converts HEIC/HEIF image to JPG type, without any dependencies
66%
Total Score
50
100
86
The package has 15 releases since January 2023, but none in the last 12 months; its latest release was over a year ago. Earlier releases were reasonably regular, which partly offsets the current pause.
The repository recorded zero commits and zero active maintainers during the last three months, consistent with a project that has been inactive since its June 2025 release.
There were no new or closed issues or pull requests in the last month, while 16 issues and 3 pull requests remain open. This supports the maintenance concern, although it is weaker evidence than the commit inactivity.
The project uses Composer build tooling, but no security-scanning tool was detected. That is a modest transparency and maintenance gap rather than evidence of an unsafe release.
The sole workflow was fully analyzed with no dangerous triggers, untrusted checkouts, or audit findings. However, all 6 action references are unpinned, leaving avoidable supply-chain hygiene risk.
| Title | Versions | Severity |
|---|---|---|
CVE-2024-48514 maestroerror/php-heic-to-jpg is vulnerable to Improper Control of Generation of Code ('Code Injection') in versions 0.0.0 - 1.0.5. | 0.0.0 - 1.0.5 | Critical |
| Dependency | Last Release | Score |
|---|---|---|
maestroerror/heif-converter Version 0.2 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.