It includes a clear Apache-2.0 license, a README, tests, and a matching organization-backed repository. The single runtime dependency and lack of install scripts reduce routine integration risk, but the project has shown no maintenance activity since March 2015.
44%
Total Score
50
100
69
83
This package has only one release, published more than 11 years ago, with no releases in the last 12 months. Its clear license, README, and tests improve transparency but do not offset the lack of release history.
There were no commits and no active maintainers in the last three months, consistent with the repository having been untouched since March 2015. The organization-owned repository provides backing context, but no observed activity supports continued maintenance.
The repository has zero stars and forks and only one watcher, providing little supporting evidence of adoption or community maintenance. Popularity is not decisive for a small package, so this is secondary to the inactivity evidence.
Composer build tooling is present, but no security scanning tools were detected. For this small, old package that is a hygiene gap rather than a decisive dependency risk.
The repository has no security policy. This reduces disclosure transparency, but for a small package with no recent activity it is a secondary concern rather than the main reason to avoid adoption.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
monolog/monolog Version * | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.