Tests, an MIT license, and no install-time scripts are reassuring, while the two runtime dependencies keep the package simple. The missing README and absent security scanning weaken transparency for a library.
42%
Total Score
0
100
50
75
This package has only one release, published about 20 months ago, with no releases in the last 12 months. That provides strong evidence of an unmaintained or abandoned dependency.
The repository recorded zero commits and zero active maintainers in the last three months, so there is no recent maintenance activity to offset the sparse release history.
The artifact and repository include tests, but the package has no README and no changelog. A missing README is a real transparency gap for a library consumers must integrate with.
The repository has zero stars and forks and only one watcher, offering little supporting evidence of community use or review. Popularity is secondary, but it reinforces the limited maturity evidence.
Composer is used for the build, which is appropriate, but no security scanning tooling was detected. This is a modest supply-chain hygiene gap rather than evidence of abandonment by itself.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
psr/log Version ^2.0 || ^3.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.