The MIT license, stable versioning, and small dependency footprint are reassuring. The missing README and absent security policy or scanning leave limited guidance and oversight for a library this old.
38%
Total Score
0
100
60
50
The latest release was published in January 2018, and there have been no releases in more than eight years. That is strong evidence of abandonment for a dependency that may need ongoing compatibility or security maintenance.
The repository recorded zero commits and zero active maintainers in the last three months, consistent with the release history showing no activity since January 2018. This leaves no current evidence of maintenance capacity.
The package has no README, which is a documentation gap for a library consumers must integrate; the missing tests and changelog are normal for a published artifact and are not concerns here. A GitHub release exists for this version, which partly supports release transparency.
Composer is used for the build, but no security scanning tooling was detected. This is a modest transparency and maintenance gap rather than evidence of an unsafe release on its own.
No security policy is present in the repository, so there is no documented process for reporting or handling vulnerabilities. The package's long inactivity makes this oversight gap more relevant.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
graylog2/gelf-php Version ^1.4.1 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.