Framework-agnostic PHP SDK for Ranetrace: error tracking, logging, event tracking and frontend JavaScript error capture.
72%
Total Score
caution
Active but very young project with highly concentrated commits, no security policy, and two unpinned workflow actions.
The registry namespace and repository owner match, supporting package ownership, but the owner is a user account rather than an organization, so there is limited institutional backing to offset contributor concentration.
One contributor made 32 of 35 recent commits, or about 91%, leaving little demonstrated continuity if that contributor stops. The second active contributor partly offsets this but does not remove the concentration risk.
Composer build tooling is present, but no security scanning tool was detected, leaving a repository hygiene gap for a package that handles application and browser-captured data.
The repository has no security policy, so there is no documented reporting path for vulnerabilities. This lowers transparency but is not evidence of a vulnerability.
The single workflow was fully analyzed with no dangerous triggers, untrusted checkouts, script injection, or audit findings. However, both of its two action references are unpinned, which weakens build reproducibility.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
psr/log Version ^3.0 | — | — |
monolog/monolog Version ^3.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.