The MIT license, focused dependency set, and complete README make adoption straightforward. The organization-owned project is not archived, but it lacks a security policy and automated security scanning.
55%
Total Score
100
100
75
50
The package has 19 releases, but its latest release was January 5, 2022, with no releases in the last four years. That is a substantial maintenance concern for a library dependency.
The repository has 0 stars, 2 forks, and 0 watchers. Popularity is only supporting evidence, but these low engagement levels provide little external confidence or maintenance signal.
Composer build tooling is present, but no security-scanning tools were detected. This is a modest hygiene gap rather than evidence that the package is unsafe.
The repository is not archived, which preserves a path for maintenance, but it was last pushed on January 5, 2022. This supports the evidence of prolonged inactivity.
No security policy was found in the repository. For a component handling Amazon S3 credentials and storage operations, this is a transparency and response-readiness gap.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
yiisoft/yii2 Version ~2.0 | — | — |
aws/aws-sdk-php Version ~3.17 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.