The source tree is coherent, includes a usable README and license, and has no install-time scripts. Zero repository activity, no security policy, and no repository adoption provide little additional assurance.
45%
Total Score
0
100
64
83
Only three releases were published, clustered within minutes on the first release day, with none during the past 12 months. This is a substantial maintenance concern for a package consumers may depend on.
The repository recorded zero commits and zero active maintainers during the past three months, reinforcing the concern that maintenance has stopped.
The repository name matches the package, reducing identity concern, but its README does not mention the package. That leaves a modest uncertainty about how clearly the source documents the published package.
The repository has zero stars, forks, and watchers. Popularity is not required for a small package, but this provides no supporting evidence of adoption or community oversight.
The repository has no security policy. This is a secondary transparency gap, especially for a package that handles uploaded images and external links, but it is not severe on its own.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
spatie/image Version ^3.0 | — | — |
guzzlehttp/guzzle Version ^7.0 | — | — |
illuminate/events Version ^10.0 || ^11.0 || ^12.0 || ^13.0 | — | — |
codex-team/editor.js Version * | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.