The MIT license, release notes, README, and matching repository support transparent use. A single maintainer, no security policy, and limited recent project activity leave maintenance capacity and oversight relatively thin.
64%
Total Score
50
100
88
50
Only one account has registry publishing access, leaving limited visible publishing redundancy. This is a user-owned project rather than organization-backed publishing, so the small maintainer base is a real though not severe concern.
Although the package has 55 releases, only one was published in the last 12 months, indicating a markedly slower release cadence for a maintained fork.
The repository recorded zero commits and zero active maintainers in the last three months, weakening evidence of ongoing maintenance despite the recent release.
Composer build tooling is present, but no security scanning tools are reported, leaving a modest oversight gap for a package that handles file operations.
The repository has no security policy, reducing transparency about vulnerability reporting and maintainer response expectations.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
league/flysystem Version ^3.0 | — | — |
laravel/framework Version ^9.0|^10.0|^11.0|^12.0|^13.0 | — | — |
intervention/image-laravel Version ^1.2.0|dev-feature/laravel-13 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.