The repository is small and has no security policy, while the README leaves usage marked TODO. It does include tests, a changelog, release notes, and an MIT declaration, but the long silence makes this a poor long-term dependency.
40%
Total Score
38
50
69
83
There have been no commits and no active maintainers in the last three months, consistent with the package's multi-year release silence. This materially raises abandonment risk.
Sixteen runtime dependencies create a relatively broad maintenance surface for a small package. The signal does not show that any dependency is abandoned or unsafe, so this is a modest concern rather than a severe one.
Only one registry account can publish the package, leaving little visible publishing redundancy. The linked repository is also owned by that individual, so there is no organizational backing shown to offset the thin maintainer base.
The artifact has a README and changelog, and the repository has tests and changelog support; release notes also document this version. The README's usage section remains TODO, limiting consumer guidance.
The registry namespace and repository are owned by the same individual account, and no organization backing is shown. This is consistent ownership but provides limited continuity if that maintainer stops work.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
psr/log Version ^1.1 | — | — |
pimple/pimple Version ^3.0 | — | — |
symfony/cache Version ^3.3 || ^4.3 || ^5.0 | — | — |
monolog/monolog Version ^1.22 || ^2.0 | — | — |
psr/simple-cache Version ^1.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.