The package offers little consumer documentation and no published security policy. Its MIT license, stable version, matching repository, and lack of install-time scripts are reassuring, but they do not offset the maintenance risk.
43%
Total Score
0
75
75
This is a 1,600-day-old package with only one release and no releases in the last 12 months, providing strong evidence of stalled maintenance.
The repository recorded zero commits and zero active maintainers over the last three months, consistent with the long release gap and increasing abandonment risk.
The published package has no README, which makes a small library harder for consumers to understand and integrate; the absence of tests and a changelog is normal for the artifact and is not penalized.
Composer is used for the build, but no security-scanning tool is present, leaving less evidence of routine dependency or code security checks.
The linked repository has no security policy, reducing transparency for reporting and handling vulnerabilities in a package intended for application logging.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
psr/log Version ^1.1 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.