Package Health

wonder-image/app

The project has substantial recent development, repository tests, changelog support, build tooling, and security scanning. Its prerelease-heavy history, single registry publisher, absent security policy, and broad runtime dependency set warrant extra maintenance scrutiny.

Latest v2.1.0PackagistPackagist

70%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

70

Dependencies
Dependencies
Evaluates the health and security of package dependencies

50

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

93

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

50

Health Score Breakdown

Dependency profilecaution

The package declares 13 runtime dependencies spanning payments, email, authentication, image processing, and document generation. This broad dependency surface increases maintenance and transitive-risk burden compared with a narrowly scoped library.

Maintainerscaution

Only one account has registry publish access, which is a narrow publishing path. Repository activity shows two active contributors, partly compensating for the registry-side concentration but not eliminating the release-account dependency.

Project backingcaution

The repository is owned by a user account rather than an organization, so there is no provided organizational backing to offset the narrow maintainer base. The two active contributors provide some practical compensation.

Repo issue activitycaution

The repository has four open issues but no issues or pull requests were opened or closed in the last month. This is a small transparency concern, though it is outweighed by the strong recent commit activity.

Security policycaution

No repository security policy was found. For a framework with authentication, payments, email, and other integrations, the absence of a documented vulnerability-reporting process is a meaningful transparency gap.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

Andrea Marinoni

Direct Dependencies

DependencyLast ReleaseScore
fpdf/fpdf
Version ^1.86
klaviyo/api
Version ^18.0
firebase/php-jwt
Version ^6.11
vlucas/phpdotenv
Version ^5.6
composer/composer
Version ^2.7

Weekly Downloads

Info

Last Published
5 months ago
Created
3 years ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform