Documentation, licensing, repository alignment, and organization backing are solid. The small project footprint and workflow hygiene warrant caution before adopting it.
54%
Total Score
75
93
50
The package has made only three releases, all within about eight days in 2025, and none in the last 12 months. That release gap raises maintenance and abandonment concerns for this young package.
The repository recorded no commits and no active maintainers in the last three months. Although it was pushed more recently than the last package release, current development activity is not evident.
The repository has no security policy. This is a transparency gap for a package handling Kafka integrations, though Dependabot provides some compensating security tooling.
The audit found a high-confidence bot-conditions issue in the Dependabot auto-merge workflow, and all 12 analyzed action references are unpinned. The pull-request-target workflow had no untrusted checkout or script-injection sink, which limits the severity.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
aryeo/avro-php Version 1.1.0 | — | — |
spatie/laravel-data Version ^4.15 | — | — |
illuminate/contracts Version ^10.45||^11.0||^12.0 | — | — |
mateusjunges/laravel-kafka Version ^2.3 | — | — |
spatie/laravel-package-tools Version ^1.16 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.