The MIT license, focused dependency set, release notes, and organization-backed repository improve transparency. The small codebase has no tests or security policy, so maintenance and review coverage remain limited.
58%
Total Score
50
100
69
75
This is the only release, published over two years ago, with no releases in the last 12 months. That materially raises abandonment risk for a dependency.
There were no commits and no active maintainers in the last three months, consistent with the release history and indicating currently inactive maintenance.
The repository has zero stars and forks and one watcher. Popularity is only supporting evidence, but these counts provide little external evidence of adoption or review.
Composer is used for the build, but no security-scanning tools are configured. For a small package this is a modest transparency and review gap, not evidence of unsafe behavior.
The repository has no security policy. This weakens its vulnerability-reporting transparency, although the package's small scope limits the significance of the gap.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
monolog/monolog Version ^2.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.