Logger Module for pantono
56%
Total Score
caution
Usable with caveats: proprietary licensing and no recent commits weaken confidence despite frequent releases.
The package declares a proprietary license, so it is licensed but does not provide the transparent open-source terms expected for an open-source dependency. No license file or repository license provides additional clarity.
The package has no README, which makes integration harder for consumers of this library. Missing tests and a changelog are normal packaging practice and do not add concern here.
The repository recorded zero commits and zero active maintainers in the last three months, which raises maintenance concerns. The repository was pushed recently and the registry has continued releasing versions, so this is caution rather than abandonment evidence.
Composer build tooling is present, but no security-scanning tooling was detected. That is a modest transparency and maintenance gap, not evidence that the package is unsafe.
The repository has no security policy, leaving no documented process for reporting or handling vulnerabilities. This is a documentation gap with limited weight given the other available project evidence.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
psr/log Version ^3.0 | — | — |
pantono/phinx Version ^0.16.3 | — | — |
pantono/database Version ^1.0 | — | — |
pantono/hydrator Version ^1.0 | — | — |
guzzlehttp/guzzle Version ^7.10 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.