Package Health

tobimori/kirby-thumbhash

It is MIT-licensed, documented, and has no install-time scripts or risky workflows. A one-person project with no security policy offers less operational depth.

Latest 2.1.1PackagistPackagist

76%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

75

Dependencies
Dependencies
Evaluates the health and security of package dependencies

100

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

94

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

90

Health Score Breakdown

Maintainerscaution

Only one account has registry publishing access. The matching repository and ongoing release history provide some compensation, but a single maintainer leaves limited continuity if that person becomes unavailable.

Repo commit activitycaution

There were no commits and no active maintainers in the last three months, which reduces evidence of ongoing development, although the recent release and repository push partly compensate.

Repo toolingcaution

The repository uses Composer, but no security scanning tool is configured. The missing scan is a modest transparency gap rather than a severe concern for this small PHP plugin.

Security policycaution

The repository has no published security policy, leaving no clear process for reporting vulnerabilities or receiving security guidance.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

Tobias Möritz

Direct Dependencies

DependencyLast ReleaseScore
srwiez/thumbhash
Version ^1.1
—
—
getkirby/composer-installer
Version ^1.2
—
—

Weekly Downloads

Info

Last Published
6 months ago
Created
3 years ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform