The package has clear documentation, licensing, and organizational ownership, with no install-time scripts or registry deprecation. Its small project footprint and limited maintenance evidence make long-term support less certain.
58%
Total Score
75
100
88
67
Only two releases exist, and the latest was published over a year ago; this indicates limited release history and a meaningful maintenance concern for a client handling certificates.
There were no commits and no active maintainers in the last three months, so current development activity is not visible even though the repository remains available.
Composer build tooling is present, but no security scanning tools were detected; that is a modest transparency and maintenance gap for a package handling certificate operations.
The repository has no security policy, leaving no documented process for reporting or handling vulnerabilities.
No GitHub Actions workflows were present, so the audit found no workflow hazards; this also means there is no observed automated build or security workflow to support release assurance.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
league/flysystem Version ^1.0|^3.0 | — | — |
guzzlehttp/guzzle Version ^6.3|^7.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.