The organization-backed repository is not archived, and the release declares Apache-2.0 with a usable README. No commits occurred in the last three months, no releases appeared in over three years, and repository security scanning is absent.
15%
Total Score
50
50
50
Packagist marks the entire package as abandoned and points consumers toward open-telemetry/exporter-* replacements. This is a severe adoption risk even though the repository itself is not archived.
The package has had no releases in the last 12 months; its latest release was over three years ago despite 16 prior releases. That indicates the published package line has effectively stopped.
The repository recorded zero commits and zero active maintainers during the last three months. This strongly supports an abandonment concern rather than a merely slow release cadence.
The repository has only 1 star and 1 fork, offering little supporting evidence of a broad active user or contributor base. Popularity is secondary, but it reinforces the maintenance concerns.
The repository has no security policy. This is a transparency and maintenance gap, particularly for an observability integration package, with no provided evidence compensating for it.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
psr/log Version ^1.1|^2.0|^3.0 | — | — |
open-telemetry/api Version ^1.0 | — | — |
open-telemetry/sdk Version ^1.0 | — | — |
php-http/discovery Version ^1.14 | — | — |
open-telemetry/context Version ^1.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.