The package is small but includes tests, a changelog, and clear licensing. Recent maintenance is concentrated in one contributor, and the repository has no security policy or README reference to the package.
68%
Total Score
67
100
93
83
All 2 recent commits came from one contributor, leaving maintenance dependent on a single active individual despite organization ownership.
There were 2 commits in the last 3 months, which shows some recent activity but a relatively light maintenance pace.
The repository name does not match the package name and its README does not mention the package, creating some uncertainty about the repository-to-package link even though the repository contents are package-specific.
The repository has no published security policy, leaving vulnerability-reporting and response expectations undocumented.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
league/flysystem Version ^3.12.3 | — | — |
league/flysystem-sftp-v3 Version ^3.12.3 | — | — |
conductor/application-orchestration Version ^4.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.