The release is stable, licensed, documented, and has a clear package layout with declared dependencies. Its package-level deprecation, archived repository, and zero recent commits indicate that it should not be adopted for new projects.
12%
Total Score
0
100
57
67
Packagist marks the entire package as abandoned and names co-stack/logs as its replacement. Package-level deprecation is a severe adoption concern even though it does not prove maliciousness.
The package has 22 releases since May 2016, but it has had no releases in the last 12 months and its latest release was November 29, 2021. The long release gap supports the abandonment concern.
The repository recorded zero commits and zero active maintainers in the last three months. This confirms that current maintenance capacity is absent.
The linked repository is archived, with its last push on January 16, 2022. An archived source repository strongly indicates the package is no longer maintained.
The package declares a post-autoload-dump lifecycle script. A lifecycle script adds install-time execution surface, but no evidence here shows that it is unsafe or unusually broad.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
psr/log Version ^1.0 | — | — |
typo3/cms-core Version ^9.5 || ^10.4 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.