Its MIT declaration and lack of install scripts are positives. The repository has no security policy or security scanning, so adopting it carries avoidable transparency risk.
38%
Total Score
40
25
The artifact and linked repository each contain only composer.json, with no implementation files visible. That is unusually thin for a package described as sending logs to multiple destinations and makes the release difficult to assess.
This release was published about 20 months ago, and it is the package's only release; there have been no releases in the last 12 months. That provides little evidence of active maintenance.
The package has no README, while tests and a changelog being absent are normal for a published artifact. Missing consumer documentation is still a meaningful gap for a library with multiple integrations.
The linked repository is named artefact rather than sfera, and the collected data does not show the package name in its README. The repository may not actually be the source for this package.
The repository has zero stars and forks and only one watcher. Popularity is supporting evidence rather than a verdict, but these figures offer no external evidence of adoption or review.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
psr/log Version ^2.0 || ^3.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.