It is MIT-licensed, documented, and has no install-time scripts or risky workflows. A one-person project with no security policy offers less operational depth.
76%
Total Score
75
100
94
90
Only one account has registry publishing access. The matching repository and ongoing release history provide some compensation, but a single maintainer leaves limited continuity if that person becomes unavailable.
There were no commits and no active maintainers in the last three months, which reduces evidence of ongoing development, although the recent release and repository push partly compensate.
The repository uses Composer, but no security scanning tool is configured. The missing scan is a modest transparency gap rather than a severe concern for this small PHP plugin.
The repository has no published security policy, leaving no clear process for reporting vulnerabilities or receiving security guidance.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
srwiez/thumbhash Version ^1.1 | — | — |
getkirby/composer-installer Version ^1.2 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.