This is a healthy, mature release with a long release history dating to 2012, a stable v3.0.0 release, active recent publishing and repository work, a matching source repository, and substantial project scaffolding. The repository is not archived, has recent commits from two active maintainers, uses Composer and Dependabot, and shows no dangerous workflow patterns. The main concerns are concentrated commit activity, no security policy, and a CI workflow without top-level token permissions; these are meaningful hygiene and resilience gaps but do not outweigh the strong evidence of ongoing maintenance and repository/package alignment.
88%
Total Score
80
100
100
80
The repository is owned by a user account rather than an organization, so the concentrated recent commit activity represents a genuine individual-maintainer continuity concern rather than an organization handoff capability.
Two contributors were active, but the leading contributor made 87.5% of recent commits. This concentration creates some continuity risk despite the second contributor remaining active.
No security policy was found in the repository. This is a transparency and vulnerability-reporting gap, although it is not evidence that the package is unsafe or abandoned.
The only workflow lacks top-level token permissions. No top-level write permissions were observed, but explicitly restricting CI token permissions would provide stronger workflow hygiene.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
psr/log Version ^3.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.