The source is a four-file client with almost no consumer documentation, tests, or security process. Its small dependency set and MIT license reduce friction, but ongoing maintenance evidence is weak.
18%
Total Score
0
100
56
75
Packagist marks the entire package as abandoned and names levmv/amazon-s3-php as its replacement. This is a direct adoption warning and outweighs the repository's non-archived status.
The package has only 7 releases since March 2020 and none in the last 12 months; the latest release was nearly 2 years ago. This indicates weak ongoing maintenance.
The repository recorded 0 commits and 0 active maintainers in the last 3 months. Combined with no recent registry releases, this provides little evidence of active maintenance.
The artifact includes a README, but it is only 15 characters long, and the repository has no tests or changelog. Missing tests and changelog are normal packaging practice, while the extremely limited README is a minor consumer-documentation gap.
Composer is used for the build, which is appropriate, but no security scanning tools are configured. For a small package this is a hygiene gap rather than a standalone severe risk.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.