It includes a README, a small six-file tree, and no install-time scripts. The single runtime dependency keeps the package simple, but no security policy leaves little maintenance guidance. Verify licensing before adoption.
32%
Total Score
0
50
75
The package has had no release in more than 8 years: its latest release was in November 2017, with no releases in the last 12 months. Its five releases were clustered together, suggesting the project was never sustained.
The repository has had zero commits and zero active maintainers in the last 3 months, while its last push was in January 2018. This corroborates the long-standing lack of release activity and indicates abandonment risk.
No license declaration or license file was found in the package, and no repository license file was detected. This creates a material adoption and redistribution risk.
The repository name does not match the package name and its README does not mention this package. That weakens confidence that the linked repository is the package's actual source.
The repository has no security policy. For an inactive package this leaves no documented path for reporting or handling vulnerabilities.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
monolog/monolog Version 1.* | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.