The pre-1.0 API and single-person ownership increase change and continuity risk. Repository tests, release notes, dependency scanning, and a clear MIT license provide useful support, but the project remains immature.
59%
Total Score
50
100
93
50
Only one registry maintainer is listed. With a user-owned repository and no organizational backing shown, continuity depends heavily on one person.
The repository recorded zero commits and zero active maintainers during the last 3 months. This is a meaningful maintenance concern despite the newer registry release.
No security policy was found. For a package that processes local and remote images, the absence reduces vulnerability-reporting transparency.
Version 0.1.1 is not a stable major release, and the project documentation says the API may change considerably before 1.0. Developers should expect compatibility changes.
All 9 action references are unpinned, and the audit found a high-confidence bot-condition issue in a pull_request_target workflow; two workflows also grant top-level write access. No untrusted checkout or script-injection sink was found, so this is workflow hygiene and supply-chain caution rather than a severe verdict.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
league/glide-symfony Version ^2.0 | — | — |
spatie/laravel-package-tools Version ^1.16.2 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.