The package includes tests, a README, and a stable v1.4 release. Its small dependency set and lack of install scripts reduce operational friction, but it provides limited security and ownership transparency.
38%
Total Score
25
100
71
75
The latest of four releases was published on April 25, 2019, with no releases in more than seven years. This is strong evidence of abandonment for a dependency that may need ongoing maintenance.
The repository recorded zero commits and zero active maintainers during the last three months, consistent with the release history showing no activity since April 2019.
No license declaration or license file was found in the package or repository, leaving the legal terms for using this dependency unclear.
The registry lists one maintainer, which limits publishing redundancy. The linked repository is user-owned, so this is a modest concern rather than evidence of organizational backing.
The repository name matches the package, which supports the linkage, but its README does not mention the package. This creates a small transparency concern without disproving ownership.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
symfony/yaml Version ^4.2 | — | — |
monolog/monolog Version ^1.24 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.