Documentation, tests, licensing, and a small dependency set support adoption. However, the last release was about 12 years ago and the repository has had no commits for about 11 years, making maintenance risk substantial.
38%
Total Score
100
100
75
75
The package has had no release in about 12 years, with zero releases in the last 12 months; its four releases were concentrated in a few days in 2014. This is strong evidence of abandonment risk.
Composer is used as the build tool, but no security-scanning tooling is reported. The missing scanning is a minor hygiene gap, not a standalone adoption blocker.
The repository is not archived, which is a positive ownership signal, but it was last pushed about 11 years ago and therefore does not demonstrate active maintenance.
The repository has no security policy, leaving vulnerability-reporting expectations unclear. This matters more for a library handling CSRF and XSS-related functionality, although the old inactive project is the larger concern.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
psr/log Version ~1.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.