The declared proprietary license may restrict adoption, and the README is mostly template text rather than practical guidance. The repository has no security scanning, although installation scripts and dependencies are limited.
34%
Total Score
50
100
60
The manifest declares a proprietary license, so the release is licensed, but the terms may restrict redistribution or use compared with a conventional open-source license.
A release note exists for this version, and the absence of tests or a changelog in the artifact is normal packaging practice. However, the 799-character README is largely unfilled template text, limiting consumer guidance.
Only two releases were published, with the latest released in September 2018 and none in the following seven years. That is a substantial abandonment risk for a framework dependency.
The repository recorded zero commits and zero active maintainers in the last three months, while its last push was in April 2019. This provides no evidence of ongoing maintenance.
Composer is used for builds, but no security scanning tools are configured. This is a modest transparency and maintenance gap rather than evidence of a direct defect.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
monolog/monolog Version ^2.0@dev | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.