The README, tests, stable version, and small dependency surface are positives. Missing security tooling and a single-person publishing base reduce transparency and resilience.
43%
Total Score
50
100
83
75
Only one registry publishing account is listed, which limits publishing resilience. The linked repository is user-owned, so there is no organization backing shown to offset that concentration.
The package has had no release in more than five years, with only three releases overall and none in the last 12 months. This is a substantial abandonment concern despite its earlier 18-day median release interval.
The repository recorded zero commits and zero active maintainers in the last three months, consistent with the long release pause and leaving little evidence of ongoing maintenance.
The repository has zero stars and forks and only one watcher, providing little community evidence to compensate for the lack of recent maintenance.
Composer build tooling is present, but no security scanning tools were detected. That weakens development hygiene, although it is less serious than the maintenance gap.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
topthink/think-queue Version ^3.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.