The package includes a clear MIT license, README, tests, and release notes. Dependencies are small, and there are no install scripts or dangerous workflow findings. The single maintainer and limited security tooling leave less independent oversight.
64%
Total Score
50
100
88
75
One registry maintainer is consistent with an individually owned project, but it provides little redundancy if that person stops maintaining it.
The repository is owned by an individual rather than an organization, so the single-maintainer and limited redundancy concerns are not offset by visible organizational backing.
Only two releases exist, with no release in the last 12 months; the latest release was published about 18 months ago. This raises maintenance risk despite the short, regular initial release interval.
There were no commits from any active maintainer in the last three months. Combined with the absent recent registry releases, this indicates a meaningful maintenance slowdown.
The repository uses Make and Composer build tooling, but no security scanning tools were detected. This is a modest transparency and oversight gap rather than evidence of abandonment.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
psr/log Version ^2 || ^3 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.