Clear licensing, tests, release notes, and an active three-person contributor base add useful confidence. The missing security policy and an unpinned workflow action are minor transparency and build-hygiene gaps.
85%
Total Score
100
100
88
67
Composer build tooling is present, but no security-scanning tooling was detected; this is a modest assurance gap rather than evidence of abandonment.
The repository has no security policy, leaving disclosure and response expectations undocumented for a library that handles telemetry integrations.
Version 0.4.12 is not a stable major release, but it is not a prerelease and recent releases contain no prerelease versions, so the maturity concern is limited.
The single workflow was fully analyzed with no audit findings and no untrusted checkout or script-injection sinks. However, it uses a top-level write token and one unpinned action, creating minor workflow-hygiene concerns.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
nyholm/psr7 Version 1.* | — | — |
open-telemetry/sdk Version 1.* | — | — |
symfony/http-client Version 7.* | — | — |
open-telemetry/exporter-otlp Version 1.* | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.