The package is small and focused, with a clear README, stable version, and organizational ownership. There is no security policy or automated security scanning, leaving maintenance transparency thinner than ideal.
65%
Total Score
67
67
50
The package has made only 3 releases since March 2022, with one release in the last 12 months and a typical gap of about 2 years and 2 months. The recent release shows the project is not fully abandoned, but the cadence is slow.
All recent commit activity comes from one contributor, creating a fragile maintenance base. Organization ownership partly offsets this because maintenance can potentially be handed off, but no second active contributor is shown.
The repository recorded 1 commit in the last 3 months from 1 active maintainer. This shows some current activity, but provides limited evidence of sustained maintenance capacity.
Composer is used for builds, but no security-scanning tooling is present. This is a modest transparency and maintenance gap rather than evidence that the package is unsafe.
The repository has no security policy. For a package handling object-storage credentials and uploads, this leaves vulnerability-reporting expectations unclear.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
league/flysystem Version ^3.0 | — | — |
laravel/framework Version ^12.0 | ^13.0 | — | — |
larva/flysystem-kodo Version ^1.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.