The small, tested codebase has clear licensing, a matching repository, and no install-time scripts. Its workflow uses eight unpinned actions and the repository has no security policy.
58%
Total Score
75
100
90
75
The package has only two releases, both in September 2022, with no release in the last four years. The stable 2.0.0 version helps, but the long release gap lowers maintenance confidence.
The repository shows no commits or active maintainers in the last three months, consistent with activity ending nearly four years ago. Its small scope may require few changes, but this still raises abandonment risk.
No security policy was found, leaving vulnerability-reporting and response expectations undocumented. The package's small, tested codebase partly limits the significance of this transparency gap.
All eight analyzed action references are unpinned, which weakens build reproducibility. The audit found no untrusted checkouts, script injection, excessive token permissions, or other reported workflow findings.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
monolog/monolog Version ^3.0.0 | — | — |
szemul/logging-error-handling-context Version ^1.0.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.