Package Health

zguillez/php-xmlog

The artifact is simple and clearly documented, with an MIT declaration and a README. Its six-release history and single-person ownership offer little maintenance capacity, while activity has been absent since 2019. Adopt only if its limited scope and unchanged code fit your needs.

Latest v1.1.3PackagistPackagist

42%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

25

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

81

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

83

Health Score Breakdown

Release historydanger

The latest release was in January 2019, about 7 years ago, and there were no releases in the last 12 months. This is strong evidence of abandonment risk for a dependency that may need fixes.

Repo commit activitydanger

The repository recorded 0 commits and 0 active maintainers in the last 3 months, consistent with the long release gap. No provided maintenance signal compensates for this inactivity.

Maintainerscaution

Only one registry maintainer is listed, which limits publishing continuity. The repository is user-owned rather than organization-backed, and recent activity does not show an active maintainer base.

Repo toolingcaution

Composer is used as the build and dependency tool, but no security scanning tooling is present. This is a modest transparency and maintenance gap for a package with otherwise very limited project activity.

Security policycaution

The repository has no security policy. For a small, inactive package this makes vulnerability reporting less transparent, although it is secondary to the prolonged maintenance gap.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

Guillermo de la Iglesia

Direct Dependencies

No direct dependencies.

Weekly Downloads

Info

Last Published
7 years ago
Created
10 years ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform