The dependency footprint is modest and the version is a stable release. The empty README and single maintainer further limit confidence in ongoing support.
32%
Total Score
50
100
60
50
The package has had no release in about seven years, despite eight releases clustered in July 2019; this is strong evidence of abandonment risk.
The manifest declares MIT, but the artifact license file was detected as GPL-3.0. This unresolved mismatch creates a meaningful adoption and compliance concern.
A post-install command runs during installation. Install-time behavior increases operational and supply-chain exposure and warrants caution even without evidence that it is malicious.
Only one account has registry publish access. This does not prove inactivity, but it indicates a thin ownership base and increases continuity risk for an already inactive package.
The artifact includes a README file, but it contains zero characters, leaving consumers without usable integration guidance; absent tests and changelog are normal for published artifacts.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
monolog/monolog Version ^1.23 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.