The MIT license, tests, README, and release notes improve transparency, while the organization-backed repository is correctly linked. The missing security scanning and prerelease status add modest concerns beyond the long maintenance gap.
52%
Total Score
50
100
69
83
The latest release was over three years ago, with no releases in the last 12 months. This is a substantial maintenance concern despite the package having six releases overall.
There were zero commits and zero active maintainers in the last three months, consistent with a project that has been inactive for years.
One registry maintainer is not concerning by itself because the project is backed by an organization; it does not demonstrate active maintenance capacity.
There are no open issues or pull requests and no recent activity. The clean tracker is mildly positive, but it does not compensate for the absence of current development.
Composer build tooling is present, but no security-scanning tools were detected, leaving a modest transparency and maintenance gap.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
amphp/log Version v2.0.0-beta.1@dev | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.