The package has a small, understandable artifact and no install-time scripts. Its long silence, unclear licensing, and single-person publishing base make long-term fixes and safe adoption difficult.
38%
Total Score
50
63
100
The latest release was in July 2019, with no releases in over seven years. Four total releases and the absence of recent activity indicate substantial abandonment risk.
The manifest declares MIT, but the artifact license file was detected as GPL-3.0. A license file is present, yet the mismatch creates material uncertainty about the terms consumers receive.
Only one registry publishing account is listed, leaving little visible ownership redundancy if that maintainer becomes unavailable. This is a concern when combined with the long release gap.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
monolog/monolog Version ^1.23 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.