The MIT license, matching repository, and working release notes improve transparency. Its small codebase has seven runtime dependencies and no security scanning, so maintenance burden and review coverage remain limited.
42%
Total Score
0
50
75
50
The package has had only two releases, both in December 2021, and none in the last 12 months; the latest release is nearly five years old. This is strong evidence of abandonment risk for a dependency.
The repository recorded zero commits and zero active maintainers in the last three months, consistent with the package's long release silence. No provided maintenance signal compensates for this inactivity.
The package declares seven runtime dependencies spanning several storage providers, increasing the surface area that must remain compatible and maintained. This is a moderate maintenance burden for a small package.
The repository has zero stars and forks and only one watcher, indicating little visible adoption or community support. Popularity is supporting evidence rather than decisive on its own, but it reinforces the maintenance concern.
Composer build tooling is present, but no security-scanning tool was detected. The build setup is a modest positive, while the missing scanning coverage is a hygiene gap.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
league/flysystem Version 1.* | — | — |
psr/simple-cache Version ^1.0 | — | — |
overtrue/flysystem-cos Version ^2.0.0 | — | — |
yzh52521/flysystem-obs Version ^1.0 | — | — |
yzh52521/flysystem-oss Version ^1.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.