The MIT license and one runtime dependency make the package straightforward to inspect and integrate. Its six-file repository has no tests or security policy, leaving little evidence of ongoing quality assurance.
38%
Total Score
0
100
75
75
The package has had only one release, published about 10 years ago, with no releases in the last 12 months. That is strong evidence of abandonment for a dependency receiving no visible updates.
The repository recorded zero commits and zero active maintainers in the last three months, consistent with the release history showing no recent maintenance.
The artifact includes a README and the version has a GitHub release, which helps consumers understand and identify it. The repository has no tests, leaving limited evidence of regression coverage for this integration package.
The repository has zero stars, one fork, and one watcher, providing little community evidence to compensate for the absence of recent maintenance.
The repository has no security policy. For a package handling file and image uploads, that is a transparency gap, although it is less significant than the long-term inactivity.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
intervention/image Version dev-master | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.