Maintenance is concentrated in one recent contributor, which limits resilience if they stop. The package is licensed, tested in the repository, and has no install scripts or deprecation notice.
78%
Total Score
83
94
75
All four commits in the last three months came from one contributor, creating a concentrated maintenance dependency even though the repository is organization-owned.
Composer is used as the build tool, but no security-scanning tools were detected, leaving automated security coverage unclear.
The repository has no security policy, which makes vulnerability reporting and response expectations less transparent.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
async-aws/s3 Version ^2.6 || ^3.0 | — | — |
flow-php/types Version self.version | — | — |
flow-php/filesystem Version self.version | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.