Package Health

amqp-client

The RabbitMQ Java client library allows Java applications to interface with RabbitMQ.

Latest 5.36.0com.rabbitmqMavenMaven

91%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

90

Dependencies
Dependencies
Evaluates the health and security of package dependencies

100

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

100

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

90

Attestations
Attestations
Measures the presence and validity of package attestations and signatures

100

Are you affected? Scan for Free

Health Score Breakdown

Repo bus factorcaution

Recent activity is concentrated: one contributor made 29 of 32 commits, or about 91%, while the second made three. The organization-owned project provides some handoff capacity, but the short-term contributor base is still a maintenance concentration risk.

Token permissionscaution

All seven workflows lack top-level permissions declarations, which weakens least-privilege transparency. However, none grants top-level write access and one workflow declares job-level permissions, so this is a hygiene concern rather than a severe risk.

Vulnerabilities

TitleVersionsSeverity
CVE-2026-106121 New
com.rabbitmq:amqp-client is vulnerable to Loop with Unreachable Exit Condition ('Infinite Loop') in versions 0.0.0 - 5.36.0.
0.0.0 - 5.36.0
Medium
CVE-2026-106122 New
com.rabbitmq:amqp-client is vulnerable to Encoding Error in versions 0.0.0 - 5.35.0.
0.0.0 - 5.35.0
Medium
AIKIDO-2026-973884
amqp-client is vulnerable to Uncontrolled Resource Consumption in versions 5.33.0 - 5.33.1.
5.33.0 - 5.33.1
High
AIKIDO-2026-359738
amqp-client is vulnerable to Information Disclosure in versions 0.0.1 - 5.34.0.
0.0.1 - 5.34.0
Medium
CVE-2026-61634
com.rabbitmq:amqp-client is vulnerable to Improper Input Validation in versions 0.0.0 - 5.33.0.
0.0.0 - 5.33.0
Low

Package versions

Maintainers

No maintainer information available.

Direct Dependencies

DependencyLast ReleaseScore
org.slf4j:slf4j-api
Version 1.7.36
—
—
io.netty:netty-transport
Version 4.2.18.Final
—
—
io.netty:netty-codec
Version 4.2.18.Final
—
—
io.netty:netty-handler
Version 4.2.18.Final
—
—
io.dropwizard.metrics:metrics-core
Version 4.2.40
—
—

Weekly Downloads

Info

Last Published
26 days ago
Created
10 years ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform