The README, MIT license, and focused dependency set make integration straightforward. Its single-owner project and limited release history leave less evidence of durable maintenance.
58%
Total Score
50
100
83
50
One registry maintainer is consistent with a small project, but the linked repository is owned by a user rather than an organization, leaving a thin visible maintainer base.
Only 4 releases exist, with 2 in the last 12 months and the latest release about 10 months ago. This provides some release continuity but limited evidence of sustained maintenance.
The repository recorded 0 commits and 0 active maintainers in the last 3 months. That is a meaningful maintenance warning for a package whose latest release is also several months old.
Composer build tooling is present, but no security-scanning tool was detected. This is a modest transparency and maintenance gap rather than evidence that the package is unsafe.
No security policy is present in the repository. For an integration library handling Sentry instrumentation, this makes vulnerability reporting and maintenance expectations less transparent.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
sentry/sentry Version ^3.21 | — | — |
guzzlehttp/guzzle Version ^7.9 | — | — |
avoutic/web-framework Version ^10 || ^11 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.