The package is small and easy to inspect, with a declared Apache-2.0 license and no install-time scripts. Its single maintainer, absent tests and security tooling, and minimal repository adoption provide little evidence of ongoing care.
42%
Total Score
50
100
61
75
This is the only release, published more than two years ago, with no releases in the last 12 months. That is strong evidence of limited maintenance rather than an established release process.
The repository is not archived, but it was last pushed in January 2020, more than six years ago. The repository's technically active status does not compensate for that prolonged inactivity.
One registry maintainer is consistent with a small user-owned project, but it also indicates a thin publishing base when combined with the repository's long inactivity.
The package includes a readable README and a GitHub release for this version, which help consumers understand and identify the release. The repository reports no tests, leaving behavior less verifiable for a logging library.
The repository has zero stars and forks and only one watcher. Popularity is not decisive by itself, but these counts provide no supporting evidence of a sustained user or contributor community.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
catfan/medoo Version ^1.7.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.