The package has a clear README, a small dependency set, and no install-time scripts. Its proprietary license is declared, but no security policy or security scanning is visible, leaving limited evidence of ongoing maintenance.
45%
Total Score
50
60
75
Only two releases were published, both within two days in December 2021, with no releases in the last 12 months. This is strong evidence that maintenance has stopped.
There are no open issues or pull requests and no issue or pull-request activity in the last month. Combined with the old release history, this provides little evidence of active maintenance.
Composer is used for builds, but no security-scanning tools are configured. The build setup is adequate, while the missing security checks modestly reduce maintenance transparency.
The repository is not archived, which is a positive, but its last push was on December 20, 2021. The lack of recent source activity materially increases abandonment risk.
The repository has no security policy. This is a transparency gap for a plugin that handles file attachments, although it is not evidence that the package is unsafe.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
composer/installers Version ^1.0.8 | — | — |
pessek/acl_builder_api Version ~4.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.