The MIT license, stable version, clear README, release notes, and repository tests provide a solid foundation. Maintenance is currently quiet, with no commits in three months and no registry releases in the last 12 months; install-time scripts and broad workflow permissions add smaller concerns.
67%
Total Score
75
100
88
50
The package declares post-install and post-update Composer scripts, which increase installation-time behavior and warrant attention. No provided signal shows that these scripts are harmful, so this is a smaller supply-chain hygiene concern rather than a severe risk.
One registry maintainer is consistent with a user-owned open-source project, and the repository owner is also an individual rather than an organization. This leaves a narrow bus factor but is not by itself evidence of abandonment.
The package has existed since May 2018 with seven releases, but it had no releases in the last 12 months and its median release interval is about 14 months. That indicates a mature but slow release cadence.
The repository recorded zero commits and zero active maintainers in the last three months. Recent repository push metadata and merged pull requests provide some counterevidence, but the direct commit signal still points to limited ongoing development.
The repository uses Make and Composer build tooling, but no security scanning tools were detected. For a small library this is a modest transparency gap, not evidence of unsafe code.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
psr/log Version ^1 || ^2 || ^3 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.