The README documents configuration, and the package has no install-time scripts. Its 13 runtime dependencies increase maintenance surface, while repository popularity is minimal.
42%
Total Score
50
69
75
The package has had no release in over four years and published only three releases, indicating a substantial abandonment risk. The repository is not archived and the package is not deprecated, which prevents this from being an extreme finding.
Thirteen runtime dependencies create a relatively broad maintenance and transitive-risk surface for a small integration package. No provided signal shows that this dependency burden is actively managed.
The repository name matches the package, but its README does not mention the package name, leaving its package-to-repository relationship less explicit. The name match partly compensates for that gap.
The repository has zero stars and forks and only one watcher, providing little evidence of community review or adoption. Popularity is supporting evidence rather than a verdict on its own.
Composer is used for builds, but no security-scanning tooling is present. This leaves dependency and source-security checks less transparent for a package with many runtime dependencies.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
psr/log Version ^1.1 | — | — |
sentry/sdk Version ^3.2 | — | — |
yiisoft/log Version ^1.0 | — | — |
psr/container Version ^1.1 | — | — |
yiisoft/router Version ^1.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.