The repository includes tests, a readable README, release notes, and no install-time scripts. Organization backing and a clean workflow audit add transparency, but the license mismatch and unpinned actions weaken reproducibility.
43%
Total Score
50
60
67
This is the only release, published nearly six years ago, with no releases in the last 12 months. That is strong evidence of abandonment risk for a package still labeled alpha.
The repository has had no commits and no active maintainers in the last three months, consistent with the long release gap. The repository is not archived, but there is no recent maintenance evidence.
The manifest declares MIT, while the repository license file was detected as BSD-3-Clause. The repository does contain a license file, but the mismatch should be resolved before adoption.
The repository has no security policy. This is a transparency and vulnerability-reporting gap, although it does not outweigh the stronger maintenance concerns on its own.
The latest version is still v0.1-alpha and all recent releases are prereleases. Consumers should expect an unstable API and limited maturity.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
psr/log Version ^1.1 | — | — |
monolog/monolog Version 2.* | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.