The project has a small user base and no security policy, which limits confidence in ongoing support. Clear licensing, organization backing, a matching repository, and a usable README provide useful transparency.
61%
Total Score
75
100
83
83
Only one registry account has publish access, which creates publishing continuity risk; the organization-owned repository provides some compensation.
The latest release was in November 2023, with no releases in the last 12 months; this is a meaningful maintenance concern for a package integrating cloud services.
The repository has zero stars and forks and only four watchers, indicating limited external adoption and review.
The project uses Composer for builds, but no security-scanning tools were detected, leaving a modest verification gap.
The repository has no security policy, so there is no documented channel or process for reporting and handling vulnerabilities.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
oasis/logging Version ^1.4 | — | — |
qcloud/cos-sdk-v5 Version ^2.6 | — | — |
oasis/aws-wrappers Version ^2.11 | — | — |
oasis/flysystem-wrappers Version ^1.2 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.