The package includes tests, a README, and a clear MIT license. Its quiet recent development and lack of a documented security process make long-term support less certain.
61%
Total Score
50
88
50
One registry account publishes the package. Because the repository is owned by the same individual, this reflects a narrow maintainer base rather than a registry-only administrative limitation.
Only two releases have appeared across about 13 months, with one release in the last 12 months and a typical gap of about 5 months. This suggests a small, slow-moving project rather than an actively evolving dependency.
The repository recorded no commits and no active maintainers during the last 3 months. The recent release shows the project is not abandoned outright, but current maintenance capacity is limited.
The repository has no security policy, leaving vulnerability reporting and response expectations undocumented. This is a genuine transparency gap for a package used in application infrastructure.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
laravel/framework Version ^10.0|^11.0|^12.0 | — | — |
intervention/image Version ^3.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.