The package includes a clear MIT license, README, and GitHub release, while its repository matches the package and is not archived. There is no security policy, so security response expectations are less clear.
67%
Total Score
50
100
50
The repository is owned by a GitHub user rather than an organization, so there is no shown organizational handoff capacity to offset the concentrated recent contribution pattern.
One contributor made all 3 commits in the last 3 months, giving the repository a 100% top-contributor share. With user-owned rather than organization-owned backing, this leaves maintenance dependent on one active person.
The repository had only 3 commits in the last 3 months. Recent release activity partly offsets the small commit volume, but the limited development activity warrants caution about maintenance capacity.
The repository has no security policy. This does not show a security defect, but it reduces transparency about how vulnerabilities are reported and handled.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
league/flysystem Version ^2.5|^3.35 | — | — |
casbin/think-authz Version ^2.0 | — | — |
topthink/framework Version ^8.1 | — | — |
topthink/think-view Version ^2.0 | — | — |
topthink/think-captcha Version ^3.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.