The source is a small 15-file project with no security policy or security-scanning tooling. Its README explains installation and usage, but the limited project evidence offers little reassurance beyond basic packaging.
43%
Total Score
50
50
The package is about 1425 days old, has only 7 releases, and has had no release in the last 12 months; its release activity stopped shortly after publication. This is a substantial maintenance and abandonment concern.
No declared license, license file, or detected repository license was found. Without licensing terms, adopting the package creates a significant legal and transparency gap.
The repository uses Composer but reports no security-scanning tools. This is a modest transparency and maintenance weakness, though it is not evidence of malicious behavior.
The repository has no security policy. That limits guidance for reporting vulnerabilities and is a minor concern for a package handling cloud-storage credentials.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
qiniu/php-sdk Version ^7.3 | — | — |
phpunit/phpunit Version ^5.0|^6.0|^9.3.3 | — | — |
qcloud/cos-sdk-v5 Version >=2.0 | — | — |
aliyuncs/oss-sdk-php Version ^2.4.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.