The package has clear documentation and a matching source repository. Its initial release burst was followed by about seven months without commits, and all four workflow actions are unpinned.
58%
Total Score
75
86
67
The package is about seven and a half months old with four releases, but all releases arrived within roughly two hours, leaving no evidence of a sustained release cadence.
The repository recorded zero commits and zero active maintainers during the last three months, indicating that maintenance has stalled after the initial extraction.
The repository has no security policy. This is a transparency gap for reporting vulnerabilities, though it is less severe for a small package with limited observed activity.
Version v0.2.2 is a non-prerelease 0.x release, so it offers some release stability but remains an early-stage API with greater compatibility risk than a stable-major package.
Both workflows were fully analyzed with no untrusted checkouts, script injection, or audit findings, but all four action references are unpinned, leaving them exposed to upstream action changes.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
league/flysystem Version ^3.30 | — | — |
symfony/filesystem Version ^7.3 | — | — |
denosyscore/contracts Version ^0.2 | — | — |
league/flysystem-aws-s3-v3 Version ^3.30 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.