Documentation, tests, licensing, and a matching source repository provide a solid baseline. The tiny public footprint, beta status, and sparse release history leave long-term support uncertain.
62%
Total Score
100
75
67
Only two releases exist across about 2 years and 8 months, with one release in the last 12 months and a roughly 2-year, 5-month median gap. The recent release shows some activity, but the history is sparse.
The repository has zero stars and forks and only one watcher. Popularity is not required for a healthy small package, but this provides little independent evidence of maturity or community support.
Composer build tooling is present, but no security-scanning tooling was detected. This is a modest transparency and maintenance gap, not a severe risk by itself.
The repository has no SECURITY.md or other detected security policy. For a dependency-injection library, this modestly limits disclosure transparency.
The assessed version is a beta release and half of recent releases are prereleases, so its API and behavior may still change. This is a meaningful caveat for a dependency.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
monolog/monolog Version ^3.10.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.