The repository has had no commits or active maintainers in the past three months, despite two releases in the last year. The small dependency set and clear MIT licensing reduce adoption friction, but missing tests and security scanning leave less evidence of ongoing quality.
62%
Total Score
50
100
83
75
The artifact includes a 2,258-character README with installation and usage examples, which is useful for a library consumer. It has no tests or changelog, but those are not expected in the published artifact; the repository also reports no tests or changelog, leaving limited verification and release documentation.
The package and repository are owned by the same individual account, rather than an organization with broader visible backing. This is consistent ownership, but it provides limited evidence of maintainer redundancy.
The repository recorded zero commits and zero active maintainers in the past three months. That weakens evidence of ongoing maintenance, although the release history shows a recent package publication.
The repository has zero stars and forks and only one watcher, indicating little visible adoption or community backup. Popularity is supporting evidence rather than a verdict, so this is a modest concern rather than a severe risk.
Composer is used for project tooling, but no security-scanning tools were detected. The absence of scanning reduces supply-chain and maintenance assurance for a package that handles uploaded files.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.