Clear licensing and a matching source repository improve transparency. Support depth is limited by one maintainer, no security policy, and a relatively broad runtime dependency set.
57%
Total Score
50
50
81
50
Eleven runtime dependencies, including several framework and service integrations, increase the package's maintenance surface and the number of upstream components it relies on.
Only one registry maintainer is listed, leaving limited publishing and support redundancy; the repository is also owned by an individual rather than an organization.
The package has 21 releases since April 2023, but none in the last 12 months and the latest was about 20 months ago, which raises maintenance concerns.
The repository recorded no commits and no active maintainers in the last 3 months, providing no recent evidence of ongoing maintenance.
Composer build tooling is present, but no security scanning tools were detected, leaving a repository hygiene gap without making the package unfit on its own.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
qiniu/php-sdk Version * | — | — |
yansongda/pay Version * | — | — |
guzzlehttp/guzzle Version * | — | — |
overtrue/easy-sms Version * | — | — |
intervention/image Version * | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.