The repository has recent work from two contributors and the package includes clear documentation and licensing. Its workflow uses broad write permissions and leaves all five actions unpinned; no security policy is provided.
78%
Total Score
67
94
50
The post-autoload-dump install-time script adds execution during dependency installation, creating some operational and review overhead even though the signal does not show harmful behavior.
The package and repository are owned by the same individual account, so there is no organization-level backing to offset the concentrated contributor activity.
Two contributors were active recently, but one made 80% of the commits, leaving maintenance somewhat concentrated despite the second contributor's activity.
Composer build tooling is present, but no security scanning tools were detected, leaving repository security hygiene less mature.
The repository has no security policy, reducing transparency about vulnerability reporting and response expectations.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
spatie/image Version 3.* | — | — |
evolution-cms/evolution Version ^3.3 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.