The small codebase has a clear MIT license, usable README, and matching organization-backed repository. It has no security policy or security scanning, and its zero-star footprint offers little external validation.
40%
Total Score
50
67
75
The latest release was published in November 2017, nearly nine years ago, with no releases in the past 12 months. Earlier releases were frequent, but the long silence is a substantial abandonment concern.
The repository recorded zero commits and zero active maintainers in the last three months, consistent with the release gap and indicating no visible ongoing maintenance.
The repository has zero stars and zero forks, with only two watchers. Popularity is supporting evidence rather than a verdict, but this provides little external validation or community support.
Composer is used for builds, which is appropriate for the package, but no security-scanning tooling is present. The missing scanning reduces assurance modestly.
The repository has no security policy, leaving no documented process for reporting or handling vulnerabilities. This is a transparency and maintenance gap, though it is not severe on its own.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
jcupitt/vips Version ^1.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.