Package Health

volcanus/file-uploader

Usable with caveats: the package is licensed, tested, actively released, and not deprecated or archived. However, repository activity is currently absent, the project has one publisher, and its CI lacks explicit token permissions and security scanning.

Latest 3.1.4PackagistPackagist

68%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

50

Dependencies
Dependencies
Evaluates the health and security of package dependencies

100

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

83

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

67

Health Score Breakdown

Maintainerscaution

Only one account has registry publishing access. That is a limited publishing base for an independently owned project and increases continuity risk if that maintainer stops maintaining it.

Project backingcaution

The repository is owned by an individual rather than an organization, so the single registry maintainer is not offset by visible organizational backing.

Release historycaution

The project has existed for over 12 years with 30 releases and a release in the last year, though only one release occurred in the last 12 months, indicating modest ongoing maintenance.

Repo commit activitycaution

The repository recorded zero commits and zero active maintainers over the last three months, which is the strongest concern because it leaves current maintenance capacity un demonstrated despite the recent release.

Repo popularitycaution

The repository has zero stars and forks and only one watcher. Popularity is supporting evidence rather than a verdict, but these numbers provide little evidence of a broad community buffer.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

k-holy

Direct Dependencies

DependencyLast ReleaseScore
psr/http-message
Version ^1.0
—
—

Weekly Downloads

Info

Last Published
9 days ago
Created
12 years ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform