Clear documentation, tests, release notes, and licensing make integration easier. The package was released today, so its maintenance record is unproven; the repository also lacks a security policy and automated security scanning.
66%
Total Score
75
88
75
This is the package's first release, published today, so there is no release cadence or long-term maintenance record yet. That is a meaningful maturity gap, though normal for a new project.
The repository shows no commits or active maintainers in the last three months, which provides no evidence of sustained maintenance; because the project was released today, this is not proof of abandonment.
Composer build tooling is present, but no security-scanning tools were detected. This is a modest transparency and maintenance concern rather than evidence that the release is unsafe.
The repository has no published security policy, leaving vulnerability-reporting and response expectations unclear for a package that sends application logs over HTTP.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
psr/log Version ^1.1 || ^2.0 || ^3.0 | — | — |
psr/http-client Version ^1.0 | — | — |
psr/http-factory Version ^1.0 | — | — |
psr/http-message Version ^1.0 || ^2.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.