The repository is organization-owned, includes tests, uses Apache-2.0 licensing, and has no install-time scripts. Ongoing maintenance is not yet demonstrated beyond the initial release.
62%
Total Score
75
100
86
83
The package was released only once, on the assessment date, so there is no release history or cadence demonstrating sustained maintenance.
There were no commits or active maintainers in the preceding three months, but the repository and package are only one day old, making this primarily an evidence gap rather than proof of abandonment.
Composer build tooling is present, supporting reproducible project structure, while no security-scanning tool is configured; for this new small package, that is a minor hygiene gap.
The repository has no security policy, reducing vulnerability-reporting transparency, though the package's very recent and small project scope limits the severity of this gap.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
intervention/image Version 4.3.2 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.