Usable but aging: the package has no releases in the last 12 months and the repo’s last push was in 2018. It’s maintained by a single person and has no security policy or CI workflow audit evidence, though the artifact includes readme/tests/changelog and a matching BSD-3-Clause license.
58%
Total Score
50
75
50
Only one maintainer has publish access, so the project has a very limited bus factor for review, releases, and responsiveness. This increases operational risk despite other packaging positives.
Releases are sparse (2 total) and there were 0 releases in the last 12 months, with the latest release dating back to 2016. That strongly suggests slow or stopped maintenance for this dependency line.
The repository is not archived, but the last push was about 7–8 years ago, which is consistent with abandonment risk over time. This lowers confidence that fixes will land quickly if something breaks.
No security policy is present in the repository metadata, so there is no documented process for reporting vulnerabilities. This is a transparency gap, especially for an older, maintenance-light project.
The workflow audit reports workflows_total = 0 and workflows_analyzed = 0, so there is no CI/workflow evidence to check pinning, permissions, or risky patterns. This lowers assurance for supply-chain hygiene.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
psr/log Version ~1.0.2 | — | — |
yiisoft/yii2 Version ~2.0 | — | — |
graylog2/gelf-php Version ~1.5 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.