The single-maintainer project has little adoption, no security policy, and no automated security scanning. Its documentation, license, tests in the repository, and clean dependency setup provide useful transparency, but do not offset the maintenance risk.
42%
Total Score
25
100
71
75
The package has only one release, published in September 2021, with no releases in roughly five years. This is strong evidence of stalled maintenance for a dependency whose compatibility may need updates.
The repository recorded zero commits and zero active maintainers in the last three months, consistent with the absence of releases and indicating no recent maintenance capacity.
One registry maintainer creates a thin ownership base and increases continuity risk, especially alongside the long period without releases or commits.
The repository has one star, zero forks, and one watcher. Low popularity is supporting evidence rather than a verdict, but it provides little evidence of broad community review or takeover resilience.
Composer build tooling is present, but no security scanning tools were detected. That weakens ongoing assurance, particularly for a project with no recent maintenance activity.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
league/flysystem Version ^1.0.69 | — | — |
psr/http-factory Version ^1.0 | — | — |
stadly/file-waiter Version >=0.2.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.