The package is clearly licensed and includes tests, a changelog, and a focused readme. Its small repository footprint, missing security policy, and unpinned workflow actions leave less assurance around long-term stewardship.
68%
Total Score
50
100
89
67
Only one registry publishing account is listed. The repository is individually owned, so this is not automatically suspicious, but it leaves limited visible publishing redundancy.
There were no commits and no active maintainers in the last three months. The February 2026 release is compensating evidence, but current development activity remains quiet.
One star and one fork indicate a very small user and contributor footprint. Popularity is only supporting evidence, but this provides little external confidence.
Composer is used for the build, but no security scanning tool was detected, leaving repository-level security checks less evident.
The repository has no security policy. For a package that reads remote HTTP resources, this reduces transparency about vulnerability reporting and handling.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
league/flysystem Version ^3.18 | — | — |
guzzlehttp/guzzle Version ^7.8 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.