The package has a small footprint and minimal supporting safeguards. Its documented usage and simple Composer dependency profile help, but there is no recent maintenance evidence to support long-term adoption.
42%
Total Score
50
100
67
75
Only four releases were published, all within a short period in July 2020, with no releases in the last 12 months and roughly six years since the latest release. This is strong evidence of abandonment risk.
The repository is not archived, but its last push was on July 24, 2020, matching the release history and reinforcing the maintenance concern.
One registry account publishes the package. Because the project is backed by a personal repository, this also indicates a thin maintainer base and limited continuity if the owner stops maintaining it.
The package contains a very small, coherent tree with a manifest, README, example, and two source files; this is consistent with a narrowly scoped library, though it offers limited evidence of maturity.
The package and repository are owned by the same individual account, confirming direct ownership but offering no organizational backing to compensate for the single-maintainer risk.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
monolog/monolog Version 2.1 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.