The MIT license, tests, clear README, and matching organization repository provide solid adoption basics. However, all 11 workflow actions are unpinned and the repository has no recent commit activity, so maintenance and build reproducibility remain concerns.
58%
Total Score
75
100
88
83
The latest release was over five years ago, despite 23 releases overall and a historically regular median interval of about 36 days. This strongly lowers confidence in ongoing maintenance, though the repository was pushed in 2023.
There were no commits and no active maintainers in the past three months. Combined with the old latest registry release, this is meaningful evidence that development has slowed substantially.
There is one open issue and one open pull request, but neither new issues nor pull requests were recorded in the past month. This is consistent with a small, quiet project and adds some maintenance concern.
Composer is used as the build tool, which fits the package ecosystem. No security scanning tools were detected, leaving a modest security-process gap.
The repository has no security policy. That weakens vulnerability-reporting transparency, although it is a process gap rather than evidence that the package is unsafe.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
monolog/monolog Version ^1.3 || ^2.0 | — | — |
laminas/laminas-stdlib Version ^3 | — | — |
laminas/laminas-servicemanager Version ^3 | — | — |
container-interop/container-interop Version ^1.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.