MIT licensing, included tests, and release notes provide useful transparency. The workflows have no detected dangerous sinks, but they use six unpinned actions and the repository has no security policy.
8%
Total Score
0
100
50
75
Packagist marks the entire package abandoned and names workofstan/backyard as a replacement, making this release unsuitable for new dependencies despite the absence of a specific withdrawal notice.
The package has 25 releases over many years, but its latest release was more than 5 years ago and it had no releases in the last 12 months, indicating abandonment rather than an active release cycle.
There were no commits and no active maintainers in the last 3 months, consistent with the archived repository and lack of ongoing maintenance.
The linked repository is archived, and its last push was more than 5 years ago, so maintenance and issue response should not be expected.
The repository has no security policy, leaving no documented channel or process for reporting vulnerabilities; this reinforces the maintenance concern but is not the main reason for the score.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
psr/log Version ~1.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.