The release is clearly licensed, documented, and installs without lifecycle scripts. Its four-year-old release history, zero releases in the last 12 months, and inactive recent commit activity reduce confidence in ongoing maintenance; no security policy adds a smaller transparency gap.
58%
Total Score
50
50
78
75
Nine runtime dependencies support several storage backends and resumable uploads, but the dependency surface is relatively broad for a small plugin and includes no development dependencies for visible testing support.
Only one registry publishing account is listed. This is consistent with the repository being owned by an individual, but it indicates limited publishing redundancy.
The repository is owned by an individual user rather than an organization, so the single maintainer signal is not offset by visible organizational backing.
The package is about 4 years old but has only 2 releases, with no releases in the last 12 months; this is a meaningful maintenance concern, though the repository is not archived.
There were zero commits and zero active maintainers in the last 3 months, while the repository was last pushed on January 31, 2024; this supports the concern that maintenance has slowed substantially.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
predis/predis Version ^1.0 | — | — |
league/flysystem Version ^1.1 | — | — |
composer/installers Version ~1.0 | — | — |
ankitpokhrel/tus-php Version ^1.3 | — | — |
league/flysystem-webdav Version ^1.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.