Risky to adopt: the package has had no release since February 2015 and no recent repository activity. Its name also borrows the identity of the much more established vimeo/psalm package, despite being unrelated, which increases dependency-selection risk.
35%
Total Score
50
100
56
90
The package is reported to borrow the identity of vimeo/psalm, with borrows_lookalike_identity true. Although artifact overlap is zero and the README describes an experimentation library, the strong naming signal means consumers could select it while intending the far more established vimeo/psalm.
The package has only four releases and none in the last 12 months; its latest release was about 11 years ago, indicating severe abandonment risk.
The repository recorded zero commits and zero active maintainers in the last 3 months, reinforcing the long-standing maintenance gap.
There were no new or closed issues or pull requests in the last month, with unresolved issues and pull requests still present; this suggests an inactive project rather than active support.
Composer is used as a build tool, but no security scanning tools are present. The missing scanning is a transparency gap, though it is secondary to the package's much older maintenance concerns.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
psr/log Version ~1.0 | — | — |
monolog/monolog Version ~1.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.