The package is small, licensed, tested, and has no install-time scripts or unnecessary runtime dependencies. Its last release and repository push were over 10 years ago, while adoption and security-process signals are minimal.
43%
Total Score
100
57
75
Only two releases were published, both in March 2016, with no releases in the last 12 months. This is strong evidence of abandonment for a package intended as a reusable logger.
The repository is not marked archived, but its last push was in March 2016. The unarchived status does not compensate for the prolonged lack of observed activity.
The repository has zero stars and forks and only one watcher. Popularity is supporting evidence rather than a verdict, but these counts provide little evidence of ongoing community support.
No security policy is present. For a small package this is a modest transparency gap, but it leaves no documented channel or process for reporting security issues.
The latest version is v0.2 rather than a stable major release, which limits maturity evidence. The absence of prerelease labeling does not offset the very short release history.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.