The source repository includes tests, a changelog, and recent activity, while the package has a clear MIT license and no install-time scripts. Its single release, pre-1.0 version, nearly empty README, and missing security policy make long-term adoption less reassuring.
64%
Total Score
75
100
71
83
One registry maintainer is consistent with an individually owned project, but it still represents a thin publishing base with limited apparent redundancy.
The artifact includes a changelog and the repository includes tests and a changelog, but the package README is only one character long, leaving consumers with almost no published usage guidance.
This package has only one release, published about 212 days ago, so there is little evidence of an established release cadence or sustained maintenance.
Composer is used as the build tool, but no security scanning tools are reported, leaving a modest repository hygiene gap.
The repository has no security policy, reducing transparency about vulnerability reporting and response expectations.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
monolog/monolog Version ^1.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.