Clear MIT licensing, repository tests, and Psalm checks add confidence. Recent work comes from one contributor, and workflow actions are not pinned. Organization backing and regular releases reduce abandonment concern.
79%
Total Score
83
100
100
75
All 6 recent commits came from a single contributor, creating concentration risk. The organization-owned repository provides some handoff capacity, but no second active contributor is shown.
No repository security policy was found, which is a transparency gap for reporting vulnerabilities, although the project does use Psalm and shows active maintenance.
Both workflows were analyzed without dangerous triggers or audit findings, but both use actions without pinned references. Missing top-level permissions blocks are acceptable here because the workflows do not request broad write access.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
monolog/monolog Version ^2.9.2 || ^3.5 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.