It has an MIT license, a substantial README, and release notes for this version. The small maintainer base, absent recent commits, missing security policy, and workflow pinning issues make long-term upkeep less certain.
58%
Total Score
50
100
94
50
There were no commits and no active maintainers in the last three months. This is the strongest maintenance concern and raises the risk that defects or compatibility issues will remain unattended.
The package runs a post-autoload-dump lifecycle script during installation. This is common in Composer packages but adds installation behavior that should be understood before adopting it.
The package and repository are owned by the same individual account, so the linkage is clear, but there is no organization backing shown to compensate for the single-person maintenance base.
The package has 9 releases over about 20 months, but only 3 in the last 12 months; the latest registry release was on October 1, 2025. This suggests activity has slowed materially.
The repository has no security policy. That weakens the documented process for reporting and handling vulnerabilities, although it does not by itself show an active security problem.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
intervention/image Version ^2.5 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.