The small codebase is easy to inspect, with a clear README and a repository that matches the package. A one-person publishing base and no security policy add uncertainty, although the MIT license and lack of install scripts are positive.
55%
Total Score
50
100
81
88
Only one registry account, Thans, has publishing access. The repository is user-owned rather than organization-backed, so the narrow publishing base provides limited continuity if that maintainer becomes inactive.
The package has only one release, published about 1 year and 11 months ago, with no releases in the last 12 months. This is a meaningful maintenance concern, though the stable 1.0 version is not itself a problem.
The repository recorded zero commits and zero active maintainers during the last 3 months. Combined with the single-release history, this raises concern that fixes and compatibility updates may not arrive.
The repository has zero stars, forks, and watchers. Popularity is only supporting evidence, so this adds limited confidence concern but does not by itself make the package unhealthy.
Composer is used as the build tool, fitting the package ecosystem, but no security-scanning tooling is configured. The missing scanning is a minor transparency gap rather than a severe health issue.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
topthink/framework Version ^6.0.0 | ^8.0.0 | — | — |
liz/flysystem-qiniu Version ^1.10 | — | — |
overtrue/flysystem-cos Version ^2.0.0 | — | — |
topthink/think-filesystem Version ^1.0 | — | — |
xxtime/flysystem-aliyun-oss Version ^1.4 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.