The project has tests, release notes, and a healthy release cadence. Its single active contributor and absent security policy leave less redundancy for long-term maintenance.
68%
Total Score
63
100
100
67
Only one registry account has publish access. That is a modest continuity concern for a user-owned project because release publishing depends on one person.
The repository owner is an individual user rather than an organization. This does not indicate a problem by itself, but it provides no organizational backing to compensate for the concentrated maintainer base.
One contributor made all two recent commits, giving the project a complete recent commit concentration in one person. The matching user-owned project provides no organizational handoff evidence to offset that dependency.
The repository has no security policy. For a storage integration package, this leaves vulnerability reporting and response expectations less transparent.
All four workflows use eight unpinned references, and a high-confidence audit found an unpinned container image in feature-tests.yml. The workflows have no untrusted checkout or script-injection findings, but the unpinned image weakens build reproducibility and supply-chain hygiene.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
webmozart/assert Version ^1.11 || ^2.0 | — | — |
illuminate/support Version ^12|^13 | — | — |
illuminate/filesystem Version ^12|^13 | — | — |
azure-oss/storage-blob-flysystem Version ^2.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.