Documentation is thorough, and the source repository includes tests, release notes, and matching package references. Apache-2.0 licensing, Composer auditing, and no install-time scripts improve transparency.
68%
Total Score
50
94
67
This is the package's first release, published today, so there is no observed release track record or demonstrated maintenance cadence yet.
No commits or active maintainers were observed in the last three months; because the repository is newly created today, this is evidence of limited history rather than confirmed abandonment.
The repository has no security policy, leaving vulnerability reporting and response expectations undocumented.
All three workflows were analyzed without failed files or dangerous sinks, and two use read-only permissions; however, all 19 action references are unpinned, weakening build reproducibility and update control.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
psr/log Version ^2.0|^3.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.