Package Health

vormkracht10/flysystem-uploadcare

Healthy and suitable to use, with a few workflow and security-hygiene caveats. It has a current release, clear documentation, tests and release notes in the repository, active organizational backing, and balanced recent contributors; the main concerns are missing security policy and permissive CI configuration.

Latest v0.6.0PackagistPackagist

78%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

90

Dependencies
Dependencies
Evaluates the health and security of package dependencies

100

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

94

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

60

Health Score Breakdown

Dangerous workflowscaution

One of five workflows uses pull_request_target for Dependabot auto-merge, which warrants review because that event can grant elevated repository context. No untrusted checkouts or script-injection patterns were detected, limiting the concern.

Lifecycle scriptscaution

The package runs a post-autoload-dump lifecycle script during installation. This is a supply-chain and installation-behavior consideration, although the signal does not show that the script is malicious or unusually broad.

Repo issue activitycaution

There are no open issues and five open pull requests, but no issues or pull requests were merged in the last month. This is a modest maintenance-process concern, partly offset by the recent release and commit activity.

Security policycaution

The repository has no security policy, leaving vulnerability-reporting expectations and supported disclosure channels undocumented. This is a transparency gap, though it does not by itself indicate abandonment.

Token permissionscaution

Four workflows lack top-level token permissions and one workflow declares top-level write access. The absence of explicit least-privilege defaults and the write-capable workflow reduce CI transparency and hardening.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

Mathieu

Direct Dependencies

DependencyLast ReleaseScore
league/flysystem
Version ^3.0
—
—
illuminate/support
Version ^9.0|^10.0|^11.0|^12.0|^13.0
—
—
uploadcare/uploadcare-php
Version ^4.1
—
—

Weekly Downloads

Info

Last Published
3 months ago
Created
3 years ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform