Author here. Built this after realizing I had zero visibility into who was probing my SaaS. Standard Laravel logging tells you about errors — not that someone ran sqlmap against your login at 3am.
Ran it in production for months tuning the confidence scoring before open sourcing. Happy to answer anything about the detection pipeline or evasion resistance.