This release appears healthy and suitable for dependency use: it has a five-year history, regular recent releases, an active non-archived organization-backed repository, four active contributors in the last three months, balanced commit concentration, tests, a clear MIT license, and no install-time lifecycle scripts. The main reservations are repository security hygiene: the only workflow uses pull_request_target with top-level write permissions, no security policy or security scanning is reported, and issue/PR activity was quiet during the last month. These concerns warrant review of the workflow before adoption but do not outweigh the strong maintenance and project-backing evidence.
84%
Total Score
90
100
88
70
The sole workflow uses pull_request_target, which requires careful review because it runs in a privileged event context; however, no untrusted checkout or script injection was detected, limiting the net concern.
There is one open issue and one open pull request, but no issues or pull requests were created or closed in the last month; this is a mild maintenance-activity gap, partly offset by recent commits and releases.
Composer build tooling is present, but no security-scanning tools are reported, leaving a security-process gap for a package that handles image data.
No repository security policy is present, reducing transparency about vulnerability reporting and response procedures.
The workflow has top-level write token permissions. This expands the impact of a workflow compromise, although no untrusted checkout or script injection was reported.
We didn't find any vulnerabilities for this package.
No maintainer information available.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.