Tests, documentation, licensing, and the minimal runtime dependency reduce adoption friction. CI references are unpinned and the repository has no security policy, so maintenance and build transparency deserve attention.
68%
Total Score
67
100
100
67
One contributor made 100% of the commits in the last three months. Organization backing provides some handoff capacity, but no second active contributor is shown to offset the concentration.
Only one commit was recorded in the last three months, with one active maintainer. The recent release history is positive, but the very limited current activity is a maintenance concern.
The repository has no security policy. For a small logging library this is not severe on its own, but it reduces transparency about how vulnerabilities would be reported and handled.
The sole workflow was fully analyzed with no untrusted checkouts, injection findings, or write-wide permissions. However, both action references are unpinned, leaving avoidable build-reproducibility and action-update risk.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
psr/log Version * | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.