Package Health

contenir/contenir-log

Tests, documentation, and licensing make the package straightforward to evaluate. However, it has stopped changing after a burst of same-day releases, and its CI uses three unpinned actions; pin v0.1.4 if adopting.

Latest v0.1.4PackagistPackagist

56%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

50

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

80

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

50

Health Score Breakdown

Repo commit activitydanger

The repository recorded zero commits and zero active maintainers during the last three months, despite the package being only about 109 days old. That is a meaningful abandonment concern rather than a cosmetic gap.

Release historycaution

The package published five releases in one burst on June 3, then had no further release for about 109 days. This suggests an immature project with uncertain ongoing maintenance.

Security policycaution

The linked repository has no security policy. For a logging library that may handle exception details and application data, this weakens vulnerability-reporting transparency.

Version stabilitycaution

v0.1.4 is not a stable major release, so API or behavior changes may still occur. It is not marked as a prerelease, which provides a small counterpoint.

Workflow auditcaution

The single workflow was fully analyzed with no dangerous triggers or audit findings, but all three action references are unpinned. This leaves avoidable build-integrity exposure while remaining a hygiene concern rather than a severe risk.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

No maintainer information available.

Direct Dependencies

DependencyLast ReleaseScore
psr/log
Version ^1.0 || ^2.0 || ^3.0
psr/container
Version ^1.0 || ^2.0
laminas/laminas-db
Version ^2.17

Weekly Downloads

Info

Last Published
3 months ago
Created
3 months ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform