Package Health

cleup/filesystem

This is a usable, actively maintained Composer package with a clear MIT license, stable 1.1.5 release, recent publishing activity, a non-archived matching repository, and no install-time lifecycle scripts or dangerous workflows. However, maintenance is concentrated entirely in one contributor, the repository has no tests or changelog, has no security policy or scanning tooling, and has essentially no adoption signals (zero stars and forks). It is reasonable for a bounded dependency, but the thin maintainer and validation base warrants caution for critical infrastructure.

Latest 1.1.5PackagistPackagist

68%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

60

Dependencies
Dependencies
Evaluates the health and security of package dependencies

50

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

83

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

90

Health Score Breakdown

Dependency profilecaution

Five runtime requirements, including PHP extensions and established filesystem-related libraries, create some environment and transitive-dependency surface but do not indicate an unusually broad dependency footprint.

Maintainerscaution

Only one registry account has publish access. This is a real publishing continuity concern, although the linked repository shows recent activity by the same owner.

Package scaffoldingcaution

A README is present and the repository uses GitHub Releases, but neither the artifact nor repository contains tests or a changelog; for a filesystem library, the absence of repository tests is a meaningful maintenance and regression risk.

Project backingcaution

The repository is owned by an individual user, not an organization, so the single-maintainer concentration is not compensated by an evident organizational handoff structure.

Repo bus factorcaution

One contributor made all 6 recent commits, producing a 100% top-contributor share and a high single-person continuity risk. The repository is user-owned rather than organization-backed, so there is no provided project-backing signal to offset this concentration.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

Eduard Y

Direct Dependencies

DependencyLast ReleaseScore
psr/http-message
Version ^2.0
—
—
phpseclib/phpseclib
Version ^3.0
—
—

Weekly Downloads

Info

Last Published
26 days ago
Created
1 year ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform