Package Health

craftcms/azure-blob

The project has clear organization backing, a recent release with notes, and a matching repository with a security policy. Maintenance has paused recently, and all three workflow action references are unpinned, leaving meaningful upkeep and build-integrity concerns.

Latest 2.1.2PackagistPackagist

68%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

67

Dependencies
Dependencies
Evaluates the health and security of package dependencies

50

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

94

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

83

Are you affected? Scan for Free

Health Score Breakdown

Dependency profilecaution

The package has four runtime dependencies, including Craft CMS and Flysystem integrations; this is a focused but nontrivial dependency surface for a storage plugin.

Repo commit activitycaution

The repository recorded zero commits and zero active maintainers in the last three months, which is a meaningful maintenance warning, although the release history and May 2026 push show recent project activity outside that window.

Repo issue activitycaution

There are only two open issues and one open pull request, but none were opened or merged in the last month, providing limited evidence of current community activity.

Repo toolingcaution

Composer build tooling is present, but no security scanning tools were detected, leaving a modest transparency and maintenance gap.

Workflow auditcaution

All three workflows were analyzed with no detected dangerous sinks or audit findings, and one workflow scopes permissions at job level while another is read-only. However, all three action references are unpinned, which weakens build reproducibility and supply-chain hygiene.

Vulnerabilities

TitleVersionsSeverity
CVE-2026-32268
craftcms/azure-blob is vulnerable to Missing Authorization in versions 2.0.0-beta.1 - 2.1.0.
2.0.0-beta.1 - 2.1.0
High
AIKIDO-2026-10272
craftcms/azure-blob is vulnerable to Information Disclosure in versions 1.0.0 - 2.1.0.
1.0.0 - 2.1.0
Critical

Package versions

Maintainers

Pixel & Tonic

Direct Dependencies

DependencyLast ReleaseScore
craftcms/cms
Version ^4.0.0-alpha.1|^5.0.0-beta.1
craftcms/flysystem
Version ^1.0.0-beta.2|^2.0.0
league/flysystem-azure-blob-storage
Version ^3.0.5

Weekly Downloads

Info

Last Published
7 months ago
Created
5 years ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform