The package is well documented, tested, licensed, and actively developed, with no deprecation or archive warning. Its young project age, highly concentrated commits, absent security policy, and unpinned workflow actions leave meaningful maintenance and build-integrity concerns.
72%
Total Score
67
100
88
67
The repository is owned by the same individual namespace as the package and is user-owned, so the source ownership is consistent but does not provide organization-level backing.
The package is only 49 days old with four releases, and releases arrived roughly every 21 hours during its initial launch. This shows early activity but provides little evidence of long-term maintenance.
Two contributors are active, but one made 42 of 44 commits, leaving maintenance heavily dependent on a single person. The repository is user-owned rather than organization-owned, so there is no shown organizational handoff capacity to offset that concentration.
Composer build tooling is present, but no security scanning tool was detected. This is a modest process gap for a package handling uploads and storage scopes.
The repository has no security policy, reducing clarity about vulnerability reporting and response for a package that includes file upload and browsing features.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
illuminate/http Version ^11.0|^12.0|^13.0 | — | — |
illuminate/view Version ^11.0|^12.0|^13.0 | — | — |
illuminate/routing Version ^11.0|^12.0|^13.0 | — | — |
illuminate/support Version ^11.0|^12.0|^13.0 | — | — |
intervention/image Version ^4.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.