The package includes tests, release notes, a matching repository, and an MIT license. Its organization-backed project is not archived, but old tooling and the absent security policy increase maintenance uncertainty.
42%
Total Score
50
100
71
75
The last release was in November 2017, with no releases in the past 12 months despite a package age of over 10 years. This is strong evidence of abandonment risk.
The repository recorded no commits and no active maintainers in the past three months, consistent with the long release gap and indicating no current maintenance activity.
The repository has 0 stars and 0 forks, providing little supporting evidence of adoption or an active user community. Popularity is only supporting evidence, so this reinforces rather than determines the score.
Composer is used for builds, but no security scanning tool is configured. The missing scanning is a modest hygiene gap alongside the broader lack of recent activity.
The repository has no security policy, leaving vulnerability reporting and response expectations undocumented. This is a transparency and maintenance gap, though it is not severe on its own.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
psr/log Version ^1.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.