The clear README, matching repository, MIT license, and small dependency set make the package easy to understand and adopt. However, its tiny codebase has no tests or security policy, so long-term maintenance depends heavily on an inactive project.
32%
Total Score
50
100
64
75
Only one release exists, published about 10 years ago, with no releases in the last 12 months. That is strong evidence of abandonment for a dependency whose compatibility may need ongoing maintenance.
The repository has had zero commits and zero active maintainers in the last three months, consistent with its last push being about 10 years ago. No provided signal shows compensating maintenance activity.
Composer is used for the build, which fits the package ecosystem. No security scanning tools are configured, a modest transparency and maintenance gap for a dependency.
The repository is not marked archived, but its last push was about 10 years ago, so the non-archived status does not offset the observed inactivity.
The repository has no security policy. This is a transparency gap, though the package is a small adapter and no other security weakness was provided.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
monolog/monolog Version 1.* | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.