MIT licensing and a very small, transparent artifact reduce adoption friction. The project lacks recent maintenance evidence, and the repository does not clearly identify this package.
38%
Total Score
0
56
75
This package has only one release, published about six years ago, with no releases in the past 12 months. That provides strong evidence of abandonment risk.
There were no commits and no active maintainers during the past three months. Combined with the old release, this indicates that maintenance has effectively stopped.
The repository name does not match the package name and its README does not mention the package. That raises uncertainty about whether the linked repository is actually the package source.
The repository has zero stars and forks and only one watcher. Popularity is not required for health, but these counters provide no supporting evidence of community adoption or oversight.
Composer is used for the build, but no security scanning tools are present. This is a modest hygiene gap rather than evidence that the package cannot be maintained.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
intervention/image Version ^2.3 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.