A non fatal version of the Monolog SlackWebhookHandler
55%
Total Score
caution
A brand-new package uses a repository that neither matches nor mentions its package.
The repository name does not match the package name, and its README does not mention the package. That raises a concrete concern that the linked repository may not actually be the package's source.
The registry namespace is patrickfischer while the linked repository is owned by the personal account zero0cool0, with no organization backing shown. This makes ownership continuity less clear when combined with the repository/package mismatch.
The package is 0 days old with four releases clustered at a median interval of 0 days, so it has not established a durable maintenance record. The rapid initial releases are not inherently negative, but there is no longer-term evidence yet.
The repository has zero commits and zero active maintainers in the last 3 months. Because the package is only 0 days old, this is partly explained by its newness, but it still leaves maintenance capacity unproven.
Composer build tooling is present, but no security scanning tools were detected. For a small package this is a hygiene gap rather than evidence of an unsafe release.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
monolog/monolog Version ^3.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.