Clear documentation, tests, release notes, and security scanning support maintainability. Organizational ownership and a matching repository make the single registry maintainer less concerning.
68%
Total Score
75
92
The package has 20 releases since 2017, but no releases in the last 12 months; the established history helps, while the recent pause lowers confidence in active maintenance.
The repository recorded no commits and no active maintainers in the last 3 months, indicating recently quiet development even though the latest release was published in June 2025.
Both workflows were fully analyzed with no dangerous triggers, untrusted checkouts, script injection, or audit findings. All four action references are unpinned, which is a modest reproducibility and supply-chain hygiene gap.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
jcupitt/vips Version ^2.1.1 || ^1.0.3 | — | — |
imagine/imagine Version ^1.0 | — | — |
phenx/php-font-lib Version ^0.5.2 || ^1.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.