It includes tests, a matching repository, clear documentation, and an MIT license. Single-person ownership, minimal adoption, and no security policy or scanning increase the maintenance risk for a messaging dependency.
45%
Total Score
50
81
50
Only one registry maintainer is listed. This creates a thin publishing base, although the repository is owned by the same individual and the package is not deprecated.
The latest release was July 28, 2021, and there were no releases in the last 12 months. Four releases show the package was published, but the long period without updates is a meaningful abandonment concern.
The repository recorded zero commits and zero active maintainers in the last three months, consistent with the package's prolonged release inactivity.
The repository has 1 star, 0 forks, and 1 watcher. Popularity is only supporting evidence, but these figures provide little evidence of a broad user or contributor community to offset the inactivity.
Composer build tooling is present, but no security scanning tools were detected. That weakens maintenance hygiene for a package handling messaging credentials and infrastructure configuration.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
aliyunmq/mq-http-sdk Version ^1.0.3 | — | — |
friendsofphp/php-cs-fixer Version ^2.18 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.