The package has a clear usage README and a stable MIT-licensed release with no install scripts or deprecation notice. Its sole repository contributor base is small, recent commit activity is absent, and the project lacks tests, security scanning, and a security policy.
57%
Total Score
63
50
83
88
Seven runtime dependencies, including framework, filesystem, cloud-adapter, and extension requirements, create meaningful version and compatibility surface for a small package.
Only one registry account has publish access. With a user-owned repository and no stronger backing signal, this leaves limited visible publishing redundancy.
The source repository is owned by an individual account rather than an organization, and no broader project backing is shown. This limits visible continuity support for a single-maintainer package.
The package is about 20 months old with 10 releases, but it has had no releases in the last 12 months; that points to slowing maintenance despite its earlier release activity.
There were zero commits and zero active maintainers in the last three months, consistent with the package's release silence and raising abandonment risk.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
ledc/container Version >=8.3.7 | — | — |
league/flysystem Version ^3.0 | — | — |
overtrue/flysystem-cos Version >=5.1 | — | — |
workerman/webman-framework Version >=1.6 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.