Tests, documentation, and licensing make the package straightforward to evaluate. However, it has stopped changing after a burst of same-day releases, and its CI uses three unpinned actions; pin v0.1.4 if adopting.
56%
Total Score
50
80
50
The repository recorded zero commits and zero active maintainers during the last three months, despite the package being only about 109 days old. That is a meaningful abandonment concern rather than a cosmetic gap.
The package published five releases in one burst on June 3, then had no further release for about 109 days. This suggests an immature project with uncertain ongoing maintenance.
The linked repository has no security policy. For a logging library that may handle exception details and application data, this weakens vulnerability-reporting transparency.
v0.1.4 is not a stable major release, so API or behavior changes may still occur. It is not marked as a prerelease, which provides a small counterpoint.
The single workflow was fully analyzed with no dangerous triggers or audit findings, but all three action references are unpinned. This leaves avoidable build-integrity exposure while remaining a hygiene concern rather than a severe risk.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
psr/log Version ^1.0 || ^2.0 || ^3.0 | — | — |
psr/container Version ^1.0 || ^2.0 | — | — |
laminas/laminas-db Version ^2.17 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.