Usable with caveats: the package is licensed, not deprecated or archived, and has recent releases, but it has no tests or changelog and recorded no repository commits in the last three months. Its pre-1.0 status, very small user base, and absent security policy make long-term maintenance less certain.
58%
Total Score
50
100
78
88
The artifact and repository contain a README but neither contains tests or a changelog. For a small library, the lack of tests reduces confidence that changes are verified and the lack of release notes reduces transparency.
The package and repository are associated with the same individual account, providing identifiable ownership, but there is no organizational backing shown to broaden maintenance capacity.
The repository recorded zero commits and zero active maintainers during the last three months. Although the registry shows two releases in the last year, the lack of recent source activity is a meaningful maintenance concern.
The repository has zero stars and forks and one watcher. Popularity is not decisive for a small package, but these counters provide little supporting evidence of community adoption or review.
Composer build tooling is present, but no security scanning tools are configured. The missing scanning is a transparency and maintenance gap, although it is not by itself evidence of an unsafe release.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
psr/log Version 1.1.4 | — | — |
hexmakina/black-box Version 0.1.* | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.