The README, tests in the repository, and modest dependency set provide useful starting points. However, the project has no recent maintenance, no security policy, and conflicting license evidence, which makes long-term support and reuse risky.
35%
Total Score
0
100
72
75
The last registry release was in October 2017, with no releases in the following 12 months of the collected history; this strongly indicates abandonment risk despite 16 historical releases.
The repository recorded zero commits and zero active maintainers in the last three months, consistent with the long release gap and leaving no evidence of current maintenance capacity.
The registry declares BSD-3-Clause while the artifact and repository license files were detected as Apache-2.0. The presence of license files is positive, but the mismatch creates uncertainty for adopters.
The repository has zero stars and zero forks, with one watcher. Popularity is only supporting evidence, but these very low adoption indicators provide little external maintenance signal.
Composer build tooling is present, but no security-scanning tools were detected. That is a hygiene gap rather than proof of unsafe code, and it adds weight to the maintenance concerns.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
psr/log Version 1.0.2 | — | — |
amphp/amp Version v1.2.2 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.