The MIT license, matching repository, tests, recent repository push, and clean workflow audit support dependable use. Keep ownership continuity in mind because recent work is concentrated in one contributor and no security policy is published.
68%
Total Score
67
100
94
83
All one recent commit came from a single contributor. Organization ownership provides some handoff capacity, but no second recent contributor is shown.
Only one commit was recorded in the last three months, by one active maintainer. The recent push prevents this from looking abandoned, but the current maintenance pace is thin.
Composer build tooling is present, but no security scanning tool was detected. This is a modest transparency gap rather than evidence of unsafe code.
The repository has no published security policy, leaving vulnerability-reporting expectations unclear for a package used in message infrastructure.
The single workflow was fully analyzed with no injection or high-severity findings, but all 3 action references are unpinned. The absence of a top-level permissions block is acceptable on its own, while unpinned actions remain a small reproducibility concern.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
bunny/bunny Version ^0.4|^0.5 | — | — |
enqueue/amqp-tools Version ^0.10 | — | — |
queue-interop/amqp-interop Version ^0.8.2 | — | — |
queue-interop/queue-interop Version ^0.8 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.