Usable with caveats: the repository is active, clearly matches the package, and the release is licensed and not deprecated. Adoption carries maintenance risk because the project is young, has one active contributor, no tests, and uses install-time scripts with write-enabled workflow permissions.
58%
Total Score
50
100
78
70
The package runs post-install and post-update Composer scripts, increasing installation complexity and the code executed during dependency operations. No provided signal shows these scripts are harmless or necessary.
Only one registry account has publishing access. This is not an administrative verdict, but it provides little redundancy for releasing fixes or responding to package issues.
A substantial README and GitHub Releases are present, but neither the package nor repository contains tests or a changelog. For an asset-processing package, the absence of tests is a real maintenance and regression concern.
The repository is owned by an individual user rather than an organization, so the single-maintainer and single-contributor concentration is not offset by visible organizational backing.
The package is only 233 days old with three releases and two releases in the last 12 months, so its long-term maintenance record is still limited despite recent publishing activity.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
smarty/smarty Version ^5.7 | — | — |
wikimedia/minify Version ^2.10 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.