The package is documented and tested, with a license and a matching source repository. Its tiny release history and years without a new registry release make future fixes uncertain; pin it only if its narrow API meets your needs.
58%
Total Score
100
75
75
The package has had only one release, 0.0.1, published about five years ago, with no releases in the last 12 months. That strongly limits evidence of ongoing maintenance.
The repository is not archived, which keeps maintenance possible, but it was last pushed about three years ago. This is weaker than an archived project but still supports concern about inactivity.
The repository has no security policy. This is a transparency and maintenance gap, though it is less concerning than the lack of recent releases because no security response process is documented.
Version 0.0.1 is not a stable major release, so compatibility and API maturity are less established. The documented initial release provides some context but does not offset the lack of subsequent versions.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
league/flysystem Version ^1.1.3 | — | — |
guzzlehttp/guzzle Version ^7.2 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.