Usable with caveats: this small package is clearly identified, licensed, and has a working README, but it has had no release for 16 months and no commits in the last 3 months. It is maintained by one person with little repository activity, so future fixes may be limited.
50%
Total Score
50
100
83
88
One registry maintainer is responsible for publishing the package. The linked repository is user-owned rather than organization-backed, so there is limited visible evidence of maintainer redundancy.
The package has only two releases and none in the last 12 months; its latest release was about 16 months ago. This is a meaningful maintenance concern for a logging integration that may need compatibility fixes.
The repository recorded zero commits and zero active maintainers during the last 3 months. The lack of recent development increases the risk that issues or dependency changes will remain unresolved.
The repository has 1 star, 0 forks, and 1 watcher. Low popularity is only supporting evidence, but it provides little community signal to offset the stale release and commit activity.
No security policy is present. For a small package this is a transparency gap, but the absence of workflows and the package's limited scope reduce its weight.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
monolog/monolog Version ^3.0 | — | — |
guzzlehttp/guzzle Version ^7.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.