It includes tests, a useful README, release notes, and a small runtime dependency set. Security scanning is absent, and publishing depends on one individual, so long-term oversight is limited.
65%
Total Score
50
100
83
83
Only one individual has registry publish access, leaving a thin publishing base; the linked repository is user-owned rather than organization-backed, so no broader operational support is shown.
The package is only 14 days old and has one release, so there is not enough release history to establish sustained maintenance; its recent launch partly explains the limited evidence.
There were zero commits and zero active maintainers during the last three months. Because the package itself is only 14 days old, this is limited evidence rather than proof of abandonment, but it weakens confidence in ongoing development.
The repository has zero stars, forks, and watchers. For a package only 14 days old this is weak supporting evidence, but it is not decisive on its own.
Composer build tooling is present, but no security-scanning tool was detected, leaving a modest repository hygiene gap.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
psr/log Version ^1.1|^2.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.