The package is small, has only two runtime dependencies, and is neither deprecated nor archived. Its single-maintainer, low-popularity project offers little resilience for future fixes.
40%
Total Score
25
25
50
No license declaration or license file was found in the package or repository. This creates a concrete legal and adoption risk for a dependency.
The latest release was about two years and seven months ago, with no releases in the last 12 months. Five releases over the package's lifetime show some initial activity, but the current gap raises abandonment concerns.
The repository recorded no commits and no active maintainers during the measured three-month window. The repository is not archived, but there is no recent activity supporting continued maintenance.
Only one registry account has publish access. A single maintainer can be sufficient for a small package, but combined with the lack of recent activity it leaves limited visible resilience for future fixes.
The package contains no README, which makes a library harder to integrate and assess. Missing tests and changelog files are normal for published artifacts and are not counted as gaps here.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
psr/log Version ^2.0 || ^3.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.