The release is licensed, documented, tested, and backed by active build and security tooling. Its early 0.x maturity and single-contributor maintenance model leave more continuity risk than an established dependency.
68%
Total Score
67
86
75
The repository is owned by an individual user rather than an organization, so there is no demonstrated organizational handoff capacity. This reinforces the single-contributor continuity concern.
The package is only 42 days old with two releases, so its maintenance pattern and compatibility track record are still limited. The two releases in that short period show active initial development but not long-term stability.
One contributor made all 20 commits in the last three months, creating a concentrated maintenance dependency. No organization backing is present to offset that concentration.
The repository has no published security policy. For a file-storage package handling uploads and delivery, that is a transparency gap, though the available Psalm and workflow evidence partly compensates for it.
Version v0.1.1 is not a stable major release, and the README explicitly says the API may still change. That is a meaningful compatibility concern for adopters.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
psr/clock Version ^1.0 | — | — |
symfony/mime Version ^6.4 || ^7.0 || ^8.0 | — | — |
yiisoft/files Version ^2.1 | — | — |
symfony/console Version ^6.4 || ^7.0 || ^8.0 | — | — |
psr/http-factory Version ^1.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.