A security policy and automated security scanning are absent. The MIT declaration, recent release, active repository status, and organization backing provide useful counterweight, but maintenance evidence remains thin.
58%
Total Score
75
100
88
75
Only 3 releases have been published since April 2014, with one release in the last 12 months and a median interval of about 12 years. The recent release helps, but the overall cadence indicates limited maintenance activity.
The repository recorded 0 commits and 0 active maintainers in the last 3 months. This is a meaningful maintenance concern, although the recent push and release provide some counterevidence.
Composer build tooling is present, but no security scanning tool was detected. For a file-upload and management component, that weakens ongoing security assurance.
The repository has no security policy. That reduces transparency about vulnerability reporting and response expectations for a package handling file uploads.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.