The clear README, small dependency surface, and matching source tree make the package straightforward to inspect and integrate. However, the latest registry release was in April 2015, with no releases in the last 12 months and no commits or active maintainers in the last three months; open work is also untouched.
40%
Total Score
25
100
75
83
The latest release was published in April 2015, with two releases overall and none in the last 12 months. This is strong evidence that the assessed release line is abandoned.
The repository recorded zero commits and zero active maintainers in the last three months. The lack of recent development materially increases abandonment risk.
There were no new or closed issues and no merged pull requests in the last month, while 52 issues and 20 pull requests remain open. This supports the maintenance concern, though it is less decisive than the release and commit history.
Composer is used for builds, which is appropriate, but no security scanning tooling was detected. This is a modest transparency and maintenance gap rather than a release-blocking issue.
The linked repository has no security policy. That reduces transparency for reporting and handling vulnerabilities, especially for a package that interacts with cloud storage.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.