The README explains installation and use, and the package has no install-time scripts. Its one-person project has no tests, security scanning, or recent activity, leaving maintenance and change safety weak.
42%
Total Score
0
75
75
This package has had only one release, with no releases in more than seven years. That is strong evidence of abandonment for a library that may need compatibility and security maintenance.
The repository recorded zero commits and zero active maintainers in the last three months, consistent with the long release gap and leaving no evidence of ongoing maintenance.
The repository has zero stars, forks, and watchers, providing no supporting evidence of external adoption or review. Popularity is only supporting evidence, so this does not determine the verdict alone.
Composer is used for the build, which supports reproducible packaging, but no security-scanning tooling is present. For a file-upload library, that weakens ongoing assurance.
The repository has no security policy, so users have no documented channel or process for reporting vulnerabilities. This is a transparency gap, though it is less significant than the lack of maintenance.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.