It includes a README, tests, and a stable 2.0.3 release, while the organization-owned repository remains unarchived. The small dependency set and absent install scripts reduce operational concern, but do not offset the lack of recent maintenance.
45%
Total Score
50
100
75
75
The latest release was published in June 2017, and there have been no releases in roughly 9 years. This is strong evidence that maintenance has stopped, despite the package having 17 historical releases.
The repository recorded zero commits and zero active maintainers in the last 3 months, consistent with the release history showing no recent updates. The unarchived status does not compensate for the absence of activity.
There was no issue or pull request activity in the last month, with one issue still open. This adds modest abandonment concern but is weaker evidence than the long release and commit gap.
The project uses Composer for its build, which is appropriate for a PHP package, but no security scanning tools were detected. The missing scanning is a hygiene gap, not the main adoption risk.
The repository has no security policy. This reduces transparency around vulnerability reporting, though the larger concern remains the lack of observable maintenance.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
psr/log Version ~1.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.