Clear licensing, release notes, and a documented test setup improve day-to-day confidence. The main limitation is workflow hygiene: all action references are unpinned and one check installs an unlocked package.
88%
Total Score
100
100
75
No repository security policy was found. This is a transparency gap for a library handling application error data, although Dependabot and active maintenance provide some compensating security practice.
All three workflows were analyzed with no high- or medium-severity findings and no untrusted checkout or script-injection sinks. However, all 10 action references are unpinned, one workflow grants top-level write access, and a high-confidence finding shows an unlocked package installed outside a lockfile, so workflow hygiene warrants caution.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
monolog/monolog Version ^2.0|^3.0 | — | — |
guzzlehttp/guzzle Version ^6.3|^7.0.1|^8.0 | — | — |
symfony/http-foundation Version >=3.3 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.