Usable with caveats: it is a small, licensed package with a matching repository and clear README, but it has had no release or commit activity for over six years. Depend on it only if its limited maintenance and lack of automated security and test coverage fit your risk tolerance.
58%
Total Score
50
78
50
The package has only three releases, with the latest published over six years ago and no releases in the last 12 months. That strongly limits evidence of ongoing maintenance, although the package is not deprecated.
There were no commits and no active maintainers in the last three months. Combined with the old last release, this is concrete evidence of an inactive project rather than merely a small contributor base.
The repository has zero stars and forks and only one watcher. Popularity is supporting evidence rather than a verdict, but these counts provide little external evidence of adoption or review.
The repository uses Composer, confirming basic project tooling, but it has no detected security scanning tools. The missing scanning is a modest transparency and maintenance gap for a dependency.
The linked repository is not archived, but its last push was over six years ago. The unarchived status is reassuring, while the stale push date supports the maintenance concern from release_history.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
alexkratky/loggerx Version ^1.0.0 | — | — |
alexkratky/filestream Version ^1.0.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.