The package is small and has no security scanning or repository security policy, while its documentation is minimal. Its MIT licensing, stable version, matching repository, and release notes provide useful transparency, but maintenance evidence is old.
58%
Total Score
75
83
50
The package has 11 releases since March 2021, but no releases in the last 12 months and its latest release was over two years ago. This indicates a mature but currently inactive release stream.
The repository recorded no commits and no active maintainers in the last three months, consistent with the package's extended release gap. This weakens evidence of ongoing maintenance.
The repository has zero stars, forks, and watchers, so there is little visible community support or independent usage evidence. Low popularity is supporting evidence only and does not outweigh the other signals by itself.
Composer is used for the build, which is appropriate, but the repository reports no security scanning tools. That is a modest transparency and maintenance gap for a file-upload component.
The repository has no security policy, leaving no stated process for reporting or handling vulnerabilities. This is a documentation gap rather than evidence that the package is unsafe.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
phpzlc/phpzlc Version 3.* | — | — |
phpzlc/upload Version 2.* | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.