The package is clearly documented, licensed, and has a small, focused dependency set with no install-time scripts. Its organization backing is reassuring, but ongoing maintenance evidence is limited; pin this version until a stronger release cadence appears.
68%
Total Score
75
100
83
75
This is a young package, released once about 164 days ago, so there is limited evidence of sustained maintenance or release responsiveness.
The repository recorded zero commits and zero active maintainers in the past three months, leaving limited evidence that issues and compatibility changes will be handled promptly.
Composer is used for the build, which fits the package ecosystem, but no security scanning tooling is present; this is a modest transparency and maintenance gap rather than a severe risk.
The repository has no security policy, reducing the clarity of vulnerability reporting and response expectations for a plugin that handles an external API key.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
craftcms/cms Version ^5.0.0 | — | — |
tinify/tinify Version ^1.0 | — | — |
spacecatninja/imager-x Version ^6.0.0-beta | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.