Tests, a release record, and an MIT declaration provide a workable foundation. The project is too new to show sustained maintenance, and its consumer documentation and security practices are still thin.
58%
Total Score
67
100
78
90
The artifact includes tests, the repository includes tests, and this exact version has GitHub release notes; the missing README is a genuine documentation gap for a storage driver consumers must integrate.
The registry namespace and repository owner match, which supports ownership continuity; the owner is an individual account, so there is no organizational backing to offset the limited maintenance history.
This is the package's first release, published less than a day ago, so there is no track record for maintenance or compatibility over time.
There were no commits or active maintainers in the measured three-month window. Because the repository was created only recently, this is primarily a lack of evidence rather than proof of abandonment, but it limits confidence.
Composer build tooling is present, but no security scanning tool was detected, leaving a modest security-process gap for a new package.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
league/flysystem Version ^3.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.