Risky to adopt for a new project because the last release and repository push were about 4 years and 6 months ago, with no recent commits. It is a small, coherent package with documentation, an MIT declaration, stable versioning, and no deprecation, but maintenance appears effectively dormant.
42%
Total Score
25
100
72
50
The package has only 3 releases, all ending about 4 years and 6 months ago, with no releases in the last 12 months. The roughly 30-day historical release interval shows an initially active project, but not current maintenance.
There were 0 commits and 0 active maintainers in the last 3 months. With no compensating recent release activity, this is strong evidence that maintenance has stopped.
The repository is owned by an individual user rather than an organization. That is not inherently unhealthy, but it offers less visible institutional backing to offset the lack of recent activity.
The repository has 1 star, 0 forks, and 1 watcher, indicating very limited external adoption or review. Low popularity is supporting evidence rather than a verdict, but it provides little confidence that issues will be surfaced or fixed.
Composer is used, showing basic ecosystem tooling, but no security scanning tools are configured. This is a transparency and maintenance weakness, though it is less significant than the absent recent activity.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
pianzhou/monolog Version ^1.02 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.