The package includes tests, a useful README, and organization ownership. Its workflow has no audit findings, but dependencies are unpinned and no security policy is present.
48%
Total Score
83
100
64
75
Only two releases were published, both within about two days in April 2024, with no release in roughly two years and five months. That strongly raises abandonment risk for a package still at version 0.0.2.
No declared license, license file, or detected repository license was found. This creates a material legal and adoption barrier for dependents.
There were no commits and no active maintainers in the last three months, consistent with more than two years without observed source updates and increasing abandonment risk.
Composer is used for builds, but no security scanning tools are configured. The missing scanning is a hygiene gap rather than proof of unsafe code.
The repository has no security policy, reducing transparency about vulnerability reporting and response expectations.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
jcupitt/vips Version 2.3.0 | — | — |
guzzlehttp/guzzle Version ^7.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.