The small dependency set, clear README, and matching repository make adoption straightforward. The organization-backed project is not archived, but its two-release history and inactive issue queue limit confidence. Pin 1.0.1 if adopting.
60%
Total Score
75
100
81
75
Only two releases were published, both in July 2024, with no releases in the last 12 months; this suggests limited ongoing maintenance for a package now about 2 years and 2 months old.
There are two open issues and no new or closed issues or pull requests in the last month, providing little evidence of active maintenance.
Composer is used as a build tool, but no security scanning tools are configured, leaving a modest transparency and maintenance gap.
The linked repository is not archived, but its last push was in July 2024, consistent with the package's limited recent activity.
The repository has no security policy, so the process for reporting and handling vulnerabilities is not documented.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
fof/upload Version ^1.2 | — | — |
guzzlehttp/guzzle Version ^7.5 | — | — |
big-dream/cdn-url-auth Version 0.0.2 | — | — |
overtrue/flysystem-cos Version ^3.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.