PSR-3 logging pipeline with 20+ handlers, 7 formatters, 6 enrichers, and fluent builder API; a building block of the open-source foundation that Jardis-generated DDD code runs on
67%
Total Score
caution
Recent releases and organization backing help, but one contributor and risky, unpinned workflow configuration lower confidence.
All six recent commits came from one contributor, creating a real continuity risk. Organization backing provides some handoff capacity, but no second active contributor is shown.
No repository security policy is present, which leaves vulnerability-reporting expectations and response procedures less transparent.
All seven action references are unpinned, and the audit found a high-confidence template-injection issue in auto-release.yml. The workflow also has top-level write permissions, so CI and release hygiene need attention.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
psr/log Version ^3.0 | — | — |
psr/container Version ^2.0 | — | — |
jardissupport/dotenv Version ^1.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.