Documentation and regression coverage are strong, and the release includes focused notes. The main limitation is that all three recent commits came from one contributor in this 34-day-old project, while workflow dependencies are unpinned and no security policy is provided.
72%
Total Score
50
100
94
83
The repository owner is a user account rather than an organization, so the concentrated contributor activity is not offset by visible organizational handoff capacity.
One contributor made all three commits in the last three months, leaving maintenance highly concentrated and creating a meaningful continuity risk.
The repository has three commits in the last three months, so it is receiving activity, but the total is still limited for a production integration library.
Composer is used for builds, but no security scanning tool was detected. This is a transparency and maintenance gap rather than evidence of unsafe code.
The repository has no security policy, so there is no documented process for reporting and handling vulnerabilities.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
psr/log Version ^2.0|^3.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.