The small source tree has no tests and no security policy, leaving little evidence of ongoing quality control. Its focused dependency set and clear README help, but not enough to offset the maintenance risk.
38%
Total Score
100
57
83
The latest release was in July 2017, with zero releases in the last 12 months across a package nearly 9 years old. That is strong evidence of abandonment for a dependency receiving no current maintenance.
The package includes a substantial README, which supports consumer transparency, but neither the artifact nor repository contains tests or a changelog. Missing tests are a meaningful quality-control gap here, while the missing changelog is normal packaging practice.
The repository has only 1 star and 1 fork, providing little supporting evidence of community review or broader maintenance capacity. Popularity is not decisive, but it does not compensate for the inactive history.
The repository is not archived, which is a compensating sign, but its last push was in October 2017 and does not offset the long period without activity.
The linked repository has no security policy, reducing transparency around vulnerability reporting for a package intended for application integration.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
intervention/image Version ^2.3@dev | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.