phpdot/tracelog appears usable and reasonably transparent, with an MIT license, a clear package structure, repository-backed tests, no install-time lifecycle scripts, no deprecation, and a recently updated unarchived repository. However, it is a young package only 53 days old with three releases, just three commits in the last three months, and all recent activity concentrated in one contributor. The absence of security scanning and a security policy also leaves hygiene gaps. Organization ownership and the repository's matching name and README reference provide some backing, but the package should be adopted with normal dependency pinning and monitoring rather than treated as mature infrastructure.
72%
Total Score
75
100
81
83
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
phpdot/contracts Version ^0.3 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.