The project includes tests, a usable README, a declared MIT license, and read-only workflow permissions. Its small single-maintainer footprint and lack of recent release or commit activity leave maintenance continuity uncertain.
66%
Total Score
50
92
83
One registry maintainer publishes the package, which creates a thin publishing base. The linked repository is also owned by the same individual, so there is no visible broader organizational backing to offset that concentration.
The package has five releases over about five years, but none in the last 12 months. That weakens confidence in ongoing maintenance despite the repository being updated more recently.
There were no commits and no active maintainers in the last three months. This is a meaningful maintenance warning, although the repository is not archived and was pushed more recently than the release cadence suggests.
The repository has no security policy, which is a transparency gap for a package presented as a web application firewall. The presence of GitGuardian scanning provides some compensating security hygiene but does not replace a reporting process.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
psr/log Version ^3.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.