The package is well documented, tested, and clearly licensed, with a focused dependency set. Its early, inactive project history and absent security controls warrant pinning this prerelease rather than relying on it for critical systems.
63%
Total Score
50
100
81
83
The package and repository are owned by the same individual account, with no organization backing shown. This is not inherently unhealthy, but it provides less visible continuity than established organizational ownership.
This is the only release, published 140 days ago, so there is not enough release history to demonstrate sustained maintenance or a proven upgrade path.
There were no commits and no active maintainers in the last three months. For a package only 140 days old, this is a meaningful sign of limited ongoing maintenance.
Composer build tooling is present, but no security scanning tools were detected. That weakens maintenance and transparency controls without making the package unfit on its own.
The repository has no security policy, leaving no published process for reporting or handling vulnerabilities.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
psr/log Version ^3.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.