Package Health

morntag/image-metadata

This is a very new, actively published 0.x package with a clear MIT license, a matching source repository, no deprecation status, no install-time lifecycle scripts, low runtime dependency complexity, and repository tests plus CI tooling. The main concerns are limited maturity evidence: the package is only hours old, has no commit or issue activity yet, has no security policy or security scanning, and its workflow does not declare top-level token permissions. These gaps do not indicate abandonment given the package's age and recent release activity, but they warrant caution before adopting it as a critical dependency; pin the version and monitor subsequent maintenance.

Latest v0.1.2PackagistPackagist

72%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

88

Dependencies
Dependencies
Evaluates the health and security of package dependencies

100

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

83

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

80

Health checks

Release historycaution

Three releases were published within roughly one day, with a median interval of about 12 hours. This demonstrates active initial publishing but provides almost no long-term maintenance history.

Repo commit activitycaution

The repository records zero commits and zero active maintainers over the last three months, but the package and repository were created only recently. The short observation window makes this a maturity gap rather than strong abandonment evidence.

Repo toolingcaution

Composer build tooling is present, but no security scanning tools are configured. Build reproducibility is supported, while security-process transparency remains limited.

Security policycaution

The repository has no security policy. This reduces vulnerability-reporting transparency, although it is a process gap rather than evidence that the package is unsafe.

Token permissionscaution

The only workflow lacks top-level token permissions and does not explicitly declare read-only permissions. This weakens CI least-privilege hygiene, though no top-level write permissions were detected.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

Joshy Merki

Direct Dependencies

No direct dependencies.

Weekly Downloads

Info

Last Published
8 days ago
Created
9 days ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform