Package Health

musoftware/logger-php

It is licensed, includes a substantial artifact and has repository security tooling. Workflow references are all unpinned, while the audit also reports a low-confidence cache concern.

Latest 5.0.3PackagistPackagist

38%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

50

Dependencies
Dependencies
Evaluates the health and security of package dependencies

100

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

75

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

83

Health Score Breakdown

Release historydanger

The package has 107 releases since 2012, but its latest release was on February 3, 2024, with no releases in the following roughly two years and seven months. That long gap raises abandonment risk despite its historically regular cadence.

Repo package mentiondanger

The repository name matches the package, but its README does not mention musoftware/logger-php and instead presents the Sentry PHP SDK. That mismatch makes package ownership and source provenance unclear, which is a material adoption concern.

Project backingcaution

The registry namespace and repository owner both identify as musoftware, but the owner is an individual account rather than an organization. This offers limited backing evidence and does not compensate for the maintenance gap.

Security policycaution

No SECURITY.md or equivalent security policy was found, leaving vulnerability reporting and response expectations unclear. Repository scanning tooling partly compensates but does not replace a policy.

Workflow auditcaution

All 12 analyzed action references are unpinned, which weakens build reproducibility, and the audit reports a low-confidence cache-poisoning pattern. All three workflows use read-only permissions and have no untrusted checkouts or script injection, so the workflow concerns remain hygiene-level rather than severe.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

Sentry

Direct Dependencies

DependencyLast ReleaseScore
psr/log
Version ^1.0|^2.0|^3.0
—
—
guzzlehttp/psr7
Version ^1.8.4|^2.1.1
—
—
symfony/options-resolver
Version ^4.4.30|^5.0.11|^6.0|^7.0
—
—
jean85/pretty-package-versions
Version ^1.5|^2.0.4
—
—

Weekly Downloads

Info

Last Published
2 years ago
Created
14 years ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform