The package is small and clearly identified, with a readable example and no install-time scripts. Its three runtime dependencies and lack of tests leave limited evidence for change safety.
48%
Total Score
0
50
79
83
Only one release exists, published on 7 February 2021, with no releases in the following five years and seven months. This is strong evidence of abandonment risk, though the stable version may be intentionally finished.
The repository recorded zero commits and zero active maintainers in the last three months, consistent with the long release gap. No newer maintenance activity compensates for this.
The package declares three runtime dependencies and no development dependencies. The dependency count is manageable, but the absence of development tooling provides little evidence of tested or controlled changes.
Composer is used for builds, which is appropriate, but no security scanning tools are configured. This reduces ongoing supply-chain oversight.
The linked repository has no security policy, leaving no documented process for reporting or handling vulnerabilities. The package's small scope limits the severity of this gap but does not remove it.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
psr/log Version ^1.1 | — | — |
monolog/monolog Version ^2.2 | — | — |
jaeger/querylist Version ^4.2 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.