It has a clear MIT license, tests, release notes, and a focused dependency set. However, there is no security policy and no recent repository activity, leaving little evidence of ongoing support.
15%
Total Score
50
100
50
83
Packagist marks the entire package as abandoned, with no replacement provided. This is a severe adoption risk because future maintenance and compatibility support should not be expected.
The package has only 2 releases, both published about 10 years ago, with no releases in the last 12 months. This strongly reinforces the evidence of abandonment.
The linked repository is archived and was last pushed about 6 years and 4 months ago. An archived source project is a severe abandonment risk for a dependency.
The repository recorded 0 commits and 0 active maintainers in the last 3 months. Together with the archived state, this indicates no current development capacity.
The repository has no security policy. For a logging library this is a transparency gap, although the archived and abandoned status is the more consequential concern.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
psr/log Version ^1.0 | — | — |
phossa2/shared Version ^2.0.21 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.