Healthy and suitable to depend on, with a small maintenance caveat: it has recent releases, repository tests, and a clear matching source repository, but recent commits all came from one contributor and the workflow lacks explicit token permissions.
78%
Total Score
63
100
94
75
The registry namespace and repository owner match, but the owner is an individual account rather than an organization, so there is no organizational maintenance redundancy to offset the concentrated contributor activity.
All three recent commits came from one contributor, so maintenance depends heavily on a single active individual and could be vulnerable to interruption.
The repository received three commits in the last three months, showing recent activity but a modest maintenance pace.
Composer build tooling is present, but no security-scanning tool was detected; this is a transparency gap rather than evidence that the package is unsafe.
The repository has no SECURITY.md or other detected security policy, leaving vulnerability reporting and response expectations undocumented.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
league/flysystem Version ^3.0 | — | — |
aliyuncs/oss-sdk-php Version ^2.7 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.