The package has tests, a clear MIT license, and organization backing. Its repository lacks a security policy and security scanning, while its workflow does not declare top-level token permissions.
62%
Total Score
100
100
78
75
The latest release was over two years ago, with no releases in the last 12 months; this is a meaningful maintenance concern despite 13 releases overall.
The repository has one star and no forks, indicating little external adoption evidence; popularity is supporting evidence rather than a decisive health measure.
Composer build tooling is present, but no security scanning tools were detected, leaving a genuine security-hygiene gap.
The linked repository is not archived, although its last push was over two years ago, consistent with the release-history concern.
The repository has no security policy, reducing transparency around vulnerability reporting and response.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
monolog/monolog Version ^2.0 || ^3.0 | — | — |
profesia/correlation-id Version ^1.0.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.