Risky to depend on: this is a one-release, pre-1.0 package with no commits in the last three months and no demonstrated release continuity. Its linked repository does not match the package name or mention it, while the README describes Monolog rather than this package, creating a serious transparency concern.
28%
Total Score
0
50
75
Only one release exists, published about 20 months ago, with no releases in the last 12 months. That provides little evidence of sustained maintenance or release continuity.
The repository had zero commits and zero active maintainers in the last three months. Together with the single historical release, this indicates a high abandonment risk.
The linked repository name does not match sfera/egora and its README does not mention the package. This raises a concrete concern that the package may be using an unrelated repository as its source.
The artifact and repository each contain only 14 files and the same minimal tree, which is not inherently unhealthy. Combined with the unrelated README content, however, this offers little transparent evidence about the package's own implementation.
The artifact includes a substantial README, tests, and a changelog, which is positive packaging hygiene. However, the README excerpt documents Monolog and instructs users to install monolog/monolog, so it does not credibly document this package.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
psr/log Version ^2.0 || ^3.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.