The package has a clear README, a matching repository, and a simple dependency profile. Its maintenance appears to have stopped after the 2018 release, with no recent commits and only two releases overall; security tooling is also absent.
42%
Total Score
25
100
72
88
Only two releases were published, both in August 2018, with no releases in the last 12 months; this indicates a long-standing maintenance gap for a library integration.
The repository recorded zero commits and zero active maintainers in the last three months, consistent with the last push occurring in 2018 and increasing abandonment risk.
One registry account has publish access. The repository owner is an individual rather than an organization, so the single-maintainer publishing base provides little redundancy if the project is unattended.
The repository has 2 stars, 1 fork, and 1 watcher. Low adoption is supporting evidence of a thin project track record, though popularity alone is not decisive.
Composer build tooling is present, but no security scanning tools are reported; this is a modest supply-chain hygiene gap without evidence of active malicious behavior.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
google/cloud-vision Version ^0.15.2 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.