The source repository has tests, release notes, and organization backing, while its MIT licensing and clean workflow audit support transparency. Maintenance has stopped for about 3 years, and workflow actions are unpinned, so pinning this version deserves caution.
62%
Total Score
75
50
88
67
Six runtime dependencies, including the MongoDB extension and related libraries, create a meaningful integration surface but are consistent with a MongoDB PSR logger.
The package has seven releases since 2018, but none in the last 12 months and the latest release was about 3 years ago, indicating likely maintenance slowdown.
The repository recorded no commits and no active maintainers in the last 3 months, consistent with the roughly 3-year release gap and raising abandonment concern.
Composer build tooling is present, but no security scanning tool was detected, leaving a modest transparency and maintenance gap.
The repository has no security policy, which weakens vulnerability-reporting transparency, though this is a secondary concern for the score.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
psr/log Version ^1.0 | — | — |
mongodb/mongodb Version ^1.0 | — | — |
subjective-php/psr-log-helper Version ^3.0 | — | — |
subjective-php/util-exceptions Version ^4.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.