It includes tests, release notes, and a repository that matches the package. The project has no security policy or automated security scanning, so long-term maintenance and review capacity remain limited.
68%
Total Score
63
100
86
75
The package and repository are owned by the same individual account, providing clear ownership but no organizational backing to offset the single-maintainer risk.
The package is only 117 days old and has two releases, with the latest published recently; this shows activity but provides limited evidence of long-term maintenance.
All three recent commits came from one contributor, so maintenance depends entirely on a single person despite the recent activity.
The repository recorded three commits in the last three months, showing recent maintenance, though the activity level is still light for a young project.
Composer build tooling is present, but no security-scanning tooling was detected, leaving automated security review coverage limited.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
monolog/monolog Version ^3.10 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.