Healthy and suitable to depend on. It has a recent stable release, clear licensing, matching organization-backed source, and no deprecation or unsafe workflow findings; maintenance is currently light and concentrated in one contributor, with no security scanning or policy.
82%
Total Score
67
100
94
75
All recent commit activity comes from one contributor, creating a maintenance concentration risk; organization backing provides some ability to hand work to others but does not remove the observed concentration.
Only one commit was recorded in the last three months, so current development activity is light, although the recent release and push provide some compensating evidence.
Composer build tooling is present, but no security scanning tools were detected, leaving a security-process gap.
No repository security policy was detected, reducing transparency about how vulnerabilities should be reported.
The repository's only workflow lacks top-level token permissions, which is less explicit than a read-only declaration but has no top-level write permission finding.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
league/flysystem Version ^3.0.0 | — | — |
league/mime-type-detection Version ^1.0.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.