The package has a clear README, matching repository, source tests, and an MIT license. Its repository has not been pushed since June 2021, and there has been no recent issue or pull-request work, leaving maintenance risk high.
40%
Total Score
67
100
69
83
The package has only one release, published about five years ago, with no releases in the last 12 months. This is strong evidence of abandonment risk for a library dependency.
The repository owner matches the registry namespace, and the owner is an individual account rather than an organization. This supports package identity but offers limited evidence of broader maintenance capacity.
There is one open issue but no new or closed issues and no pull-request activity in the last month. Combined with the old repository push, this suggests maintenance has stopped.
The repository uses Make and Composer build tooling, which supports reproducible project tasks. No security scanning tools were detected, a minor transparency and hygiene gap for a maintained dependency.
The linked repository is not archived, which is a positive maintenance signal. However, its last push was about five years ago, so this does not offset the broader inactivity evidence.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
psr/log Version ^1.1 | — | — |
phpsagas/contracts Version ^0.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.