Clear documentation, licensing, release notes, and repository tests make adoption straightforward. The project lacks a security policy, and its workflow uses five unpinned actions with an untrusted checkout.
79%
Total Score
100
100
90
75
The package is mature at over 12 years old, but only one release arrived in the last 12 months and the median interval is about 11 months. The recent 3.2.0 release and active repository provide some compensation.
The linked repository has no security policy, leaving vulnerability reporting and disclosure expectations undocumented. This is a transparency gap, though it does not by itself make the release unfit.
The only workflow uses an untrusted checkout with a pull_request_target trigger, which warrants caution even though no script injection was found. All five action references are unpinned, weakening build reproducibility; job-level permissions partly compensate for the missing top-level block.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
guzzlehttp/psr7 Version ^2.7 | — | — |
intervention/image Version ^3.3 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.