The package has a clear README, MIT licensing, release notes, and a source repository that matches the package. It has no tests or security scanning, and zero commits in the last three months leaves ongoing support unproven.
61%
Total Score
50
88
67
This is a new package, only 81 days old, with one release and no established release cadence. That limits evidence of maturity but is not, by itself, abandonment.
The repository has zero commits and zero active maintainers in the last three months. For a package released 81 days ago, this leaves ongoing maintenance capacity unproven.
Composer is used for the build, but no security scanning tool is present. This is a modest transparency and maintenance gap rather than evidence that the package is unsafe.
The repository has no security policy, leaving vulnerability-reporting expectations undocumented for a package that sends application logs to an external service.
No GitHub Actions workflows were present, so the audit found no workflow risks; this also provides no automated CI or release-verification evidence.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
monolog/monolog Version ~1.12|^2.0|^3.0 | — | — |
guzzlehttp/guzzle Version ^7.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.