Usable with caveats: the package is licensed, clearly tied to its repository, stable, and not deprecated. However, all four releases arrived within one day and there has been no commit activity or active maintainer in the last three months, leaving maintenance capacity uncertain.
58%
Total Score
50
100
81
50
The package is backed by a matching personal repository rather than an organization, so the single registry maintainer represents a genuinely narrow ownership base.
The package is young at 125 days and all four releases were published within roughly 48 minutes, showing an initial burst but not an established release pattern.
There were no commits and no active maintainers in the last three months, a meaningful warning for a backup package that may need compatibility and reliability fixes.
Composer build tooling is present, but no security scanning tools are configured, leaving a modest transparency and maintenance gap.
The linked repository is not archived, but its last push was on the same day as the releases, so this does not offset the later inactivity shown by commit activity.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
league/flysystem-aws-s3-v3 Version ^3.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.