It has a clear MIT license, a small dependency set, and no install-time scripts. The repository is not archived, but maintenance evidence is old and the package's connection to that repository is unclear.
43%
Total Score
50
100
71
83
The latest release was published in October 2019, with no releases in the last 12 months. This is strong evidence of abandonment risk for a package intended for ongoing use.
The repository recorded no commits and no active maintainers in the last 3 months, consistent with the release history showing several years without updates.
The repository name does not match the package name and its README does not mention the package, so the source linkage is not clearly established. This is a transparency concern even though subpackages can legitimately use a different repository name.
The repository uses Composer build tooling, but no security-scanning tools were detected. The missing scanning is a modest hygiene gap rather than evidence of abandonment on its own.
No security policy was found in the repository. This limits vulnerability-reporting transparency, although it is secondary to the much older maintenance evidence.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
craftcms/cms Version ^3.0.0 | — | — |
spatie/image-optimizer Version ^1.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.