Jfs upload library
38%
Total Score
unhealthy
Risky: proprietary licensing, opaque packaged files, and weak evidence of an established project
The package contains numerous files with opaque .enc names, making the shipped implementation difficult to inspect; the linked repository exposes ordinary PHP source but does not fully compensate for the artifact's lack of transparency.
The manifest declares a proprietary license, so the release is legally licensed, but that can restrict use in projects expecting an open-source dependency and provides no recognized license file for verification.
The package has no README, tests, or changelog, which weakens consumer guidance and verification for a library; the exact version does have a GitHub release, providing only limited documentation evidence.
This is the only release, published 203 days ago, so there is no established release cadence or evidence of ongoing registry maintenance.
The linked repository name does not match jfs/uploader, and no README package mention was collected, so ownership of the published package is not clearly established.
We didn't find any vulnerabilities for this package.
No maintainer information available.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.