Documentation, tests, and a release note make integration straightforward. Its small, single-maintainer footprint and unpinned workflow actions add maintenance and build-trust caveats.
67%
Total Score
50
92
50
The package has three releases over about 14 months, with only one release in the last 12 months and roughly 6–7 months between typical releases. This indicates a young project with limited release history, but not abandonment by itself.
All recent commits come from one contributor, giving the project a bus factor of one. The repository is user-owned rather than organization-owned, so there is no provided backing signal to offset that concentration.
Only one commit was recorded in the last three months, with one active maintainer. That shows some recent activity but a thin maintenance cushion for future fixes.
The repository has no security policy. For a logging integration that handles application output and webhook configuration, this weakens vulnerability-reporting transparency.
The single workflow was fully analyzed with no dangerous triggers, untrusted checkouts, or audit findings. However, both action references are unpinned, so build inputs are less reproducible; the lack of a top-level permissions block is not concerning here because the workflow has no top-level write permissions.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
illuminate/http Version ^11.0|^12.0|^13.0 | — | — |
monolog/monolog Version ^3.2 | — | — |
illuminate/support Version ^11.0|^12.0|^13.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.