Documentation, tests, and a clear source repository support continued use. The organization-owned project has limited security-process coverage, and its open pull requests show no recent movement.
56%
Total Score
50
67
50
The package has had no releases in the last 12 months, and its latest release was over five years ago. This materially raises abandonment risk despite six historical releases and a short early release interval.
The repository recorded zero commits and zero active maintainers in the last three months, consistent with a project that is no longer actively maintained.
The artifact and repository contain license files, but the detected GPL-3.0 text does not exactly match the declared GPL-3.0+ value. Licensing is present, but the mismatch warrants clarification.
There are 14 open pull requests, with no new or merged pull requests in the last month. The backlog is a maintenance warning, though the absence of open issues limits its impact.
Composer is used for builds, but no security scanning tool is configured. That reduces automated oversight for a package with a runtime dependency.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
google/cloud-storage Version ^1.23 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.