Its README, tests, MIT licensing, and version-specific release notes make adoption straightforward. A single contributor handles all recent commits, so maintenance continuity depends heavily on one maintainer.
78%
Total Score
50
100
94
83
One contributor made all 10 commits during the last 3 months, giving the project a bus factor of one. Because the owner is an individual rather than an organization, this is a meaningful continuity concern.
The repository recorded 10 commits in the last 3 months, showing recent development activity. However, the activity is concentrated in one active maintainer.
There are 5 open issues, but no issues or pull requests were opened, closed, or merged during the last month. This weakens evidence of responsive community maintenance despite the recent commits.
Composer build tooling is present, but no security scanning tool was detected. That is a transparency and maintenance-process gap, though it is not by itself evidence that the release is unsafe.
The repository has no security policy. For a file-upload and cloud-storage library, the absence of documented vulnerability reporting and handling procedures is a modest transparency concern.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
workerman/webman-framework Version ^1.5.4||^2.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.