Package Health

ulasimarsiv/upload-exif

The package has one registry maintainer, no security policy, and no security scanning. Its README appears to document a different JavaScript package, while the repository does not clearly mention this package; the MIT license and tests are positives.

Latest 1.2.9PackagistPackagist

44%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

25

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

64

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

75

Health Score Breakdown

Release historydanger

All 27 releases arrived within about three days, followed by roughly five months without a release; this bursty history provides limited evidence of sustained maintenance.

Repo commit activitydanger

The repository shows zero commits and zero active maintainers in the last three months, a strong sign that maintenance has stalled after the initial release burst.

Maintainerscaution

Only one registry account has publish access, leaving little visible publishing redundancy; the linked repository is user-owned, so organization backing does not compensate for this thin base.

Package scaffoldingcaution

The artifact includes a README, tests, a changelog, and a GitHub release, which support basic packaging transparency; however, the README content appears unrelated to this PHP package.

Repo package mentioncaution

The repository name does not match the package name and its README does not mention the package, so the source relationship is not clearly established.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

alikaankaya

Direct Dependencies

DependencyLast ReleaseScore
flarum/core
Version ^2.0
—
—
intervention/image
Version ^3.0
—
—
google/cloud-storage
Version ^1.30
—
—

Weekly Downloads

Info

Last Published
5 months ago
Created
5 months ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform