The package has no security policy or automated security scanning, and its 16 runtime dependencies increase the maintenance surface. Its MIT license and Composer build provide useful transparency, but they do not offset the project’s apparent abandonment.
28%
Total Score
0
50
64
75
The package is about 3 years old but has only 2 releases, both within roughly 2 hours in July 2023, with no releases in the last 12 months. This is strong evidence of abandonment risk.
The repository recorded 0 commits and 0 active maintainers in the last 3 months, consistent with the long release gap and indicating no recent maintenance capacity.
The package declares 16 runtime dependencies and no development dependencies, producing a relatively broad runtime maintenance surface with little visible development scaffolding.
The package includes a README and has a GitHub release for this version, which provide some consumer and release transparency. However, the README explicitly says not to use it because it is still being developed.
The linked repository name does not match the package name and its README does not mention the package, creating uncertainty that this repository is the package’s intended source.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
psr/log Version ^1.1|^2.0|^3.0 | — | — |
nyholm/psr7 Version ^1.3 | — | — |
php-di/php-di Version ^6.3 | — | — |
php-di/invoker Version ^2.3 | — | — |
monolog/monolog Version ^2.2 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.