The repository is actively maintained and includes tests, documentation, dependency scanning, and a matching source project. Its young v0.9 release line, single active contributor, missing security policy, and unpinned workflow actions warrant care for a production dependency.
68%
Total Score
70
100
94
75
Only one account has registry publish access. The organization-owned repository provides project backing, but the registry publishing path remains concentrated.
One contributor made 100% of the 9 commits in the last 3 months. Organization backing helps provide handoff capacity, but no second active contributor is shown to reduce the immediate concentration risk.
There is one open issue and one open pull request, but no issues or pull requests were created or closed in the last month. This is limited activity rather than evidence of abandonment given the recent commits.
The repository has no security policy. For a package that sends application logs and handles an API token, the missing disclosure and response guidance is a genuine transparency gap.
v0.9.0 is not a stable major release, so compatibility may still change before 1.0. It is not marked as a prerelease, which partly offsets the concern.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
monolog/monolog Version ^3.0 | — | — |
illuminate/support Version ^11.0|^12.0|^13.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.