Its five runtime dependencies add integration surface, and the project’s source could not be verified. Use knot-lib/logger instead.
12%
Total Score
100
17
Packagist marks the entire package as abandoned and names knot-lib/logger as its replacement. This directly indicates that new projects should not adopt this package.
The latest release was about 6 years and 10 months ago, with no releases in the past 12 months. This is strong evidence of abandonment risk.
Version 0.2.0 is still below a stable 1.0 release, providing limited maturity evidence; the long release gap and package deprecation reinforce the concern.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
stk2k/file Version ~0.1 | — | — |
stk2k/util Version ~0.1 | — | — |
calgamolib/config Version ~0.1 | — | — |
calgamolib/exception Version ~0.1 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.