The release includes a clear README, license, small runtime dependency set, and no install-time scripts. Maintenance and source transparency remain difficult to verify, so pinning this version is preferable to assuming ongoing support.
68%
Total Score
50
100
90
100
One registry account has publish access, which indicates a thin administrative base; this is only a supporting caution because registry access does not establish actual maintenance activity.
The package has existed since May 2020 and published 2 releases in the last 12 months, showing continued activity but a modest cadence.
| Title | Versions | Severity |
|---|---|---|
CVE-2014-8327 co-stack/fal_sftp is vulnerable to Incorrect Default Permissions in versions 0.0.0 - 0.2.6. | 0.0.0 - 0.2.6 | Medium |
| Dependency | Last Release | Score |
|---|---|---|
typo3/cms-core Version ^13.4 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.