The five-file implementation is compact, with no install-time scripts and only two runtime dependencies. Missing project safeguards and consumer documentation increase the cost of taking on an apparently abandoned library.
48%
Total Score
0
33
50
The package has had no release in about four years: its latest release was on June 1, 2022, with zero releases in the last 12 months. Its nine total releases show some earlier activity but do not offset the prolonged pause.
The repository recorded zero commits and zero active maintainers in the last three months, consistent with the long gap since the latest release. This is a meaningful abandonment concern for a dependency.
No declared license, license file, or repository license file was detected. That creates a material adoption and redistribution risk for an open-source dependency.
The package has no README, while tests and a changelog are absent in both the artifact and repository. Missing tests and changelog are normal for published artifacts, but the missing consumer documentation is a real transparency gap for a library.
The repository has no security policy. For a small five-file logger this is less serious than for a security-sensitive framework, but it still provides no documented channel or process for reporting vulnerabilities.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
psr/log Version ^3.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.