The package includes tests, recent releases, Composer tooling, and security scanning. Documentation and security-process coverage are limited, which leaves adopters with less guidance.
62%
Total Score
50
75
75
The manifest declares a proprietary license, with no detected license text or license file in the package or repository. That creates a material adoption and redistribution concern for an open-source dependency.
Tests are present in both the package context and repository, which supports maintainability. The missing README is a documentation gap for a library, while the absent changelog is not concerning because release notes are not required for every registry release.
One contributor made all commits in the last 3 months, leaving maintenance dependent on a single active person. The individual-owned repository provides no organizational handoff evidence to offset that concentration.
Only 1 commit was recorded in the last 3 months, showing limited recent source activity despite the strong registry release cadence. This is a maintenance concern, but not evidence of abandonment on its own.
The repository has no security policy, so users lack a documented process for reporting vulnerabilities or understanding security response expectations.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
psr/log Version ^1.1 || ^2.0 || ^3.0 | — | — |
ramsey/uuid Version ^4.0 | — | — |
beberlei/assert Version ^3.3 | — | — |
monolog/monolog Version ^2.0 || ^3.0 | — | — |
open-telemetry/api Version ^1.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.