This release appears suitable to depend on: it is stable, not deprecated, has a long release history with four releases in the last 12 months, and the linked organization-owned repository is active and unarchived. The package is licensed under MIT, has a clear README, changelog, and coherent source tree, with no install-time lifecycle scripts and only one runtime dependency. The main concerns are that all seven recent commits came from one contributor, the repository has no security scanning or security policy, and the project has negligible public popularity; these reduce resilience and transparency but do not indicate abandonment given the recent release and commit activity.
78%
Total Score
90
100
83
90
A substantial README and changelog are present, and the repository also has a changelog; however, neither the artifact nor repository contains tests, which is a maintenance-quality gap for a functional upload component.
All seven recent commits came from a single contributor, creating a clear bus-factor concern; organization ownership partly compensates because maintenance can potentially be handed off internally.
The repository has zero stars and forks and only two watchers, indicating limited external adoption or review; popularity is supporting evidence rather than a decisive health verdict.
Composer is used as a build tool, but no security scanning tools are configured, leaving a transparency and detection gap.
The repository has no security policy, reducing transparency about vulnerability reporting and response procedures.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.