MIT licensing, repository tests, and a clean workflow audit support adoption. Maintenance is the main concern: only one release in the last 12 months and no commits from active maintainers in the last 3 months. The missing security policy and unpinned workflow actions add modest transparency and build-hygiene risk.
63%
Total Score
67
100
79
75
The package has a long history and 34 releases, but only one release in the last 12 months, indicating a slower recent cadence than its earlier median interval of about 40 days.
There were no commits and no active maintainers in the last 3 months, which is a concrete sign of slowed maintenance and raises abandonment risk.
There are no open issues or pull requests and no recent issue or pull-request activity. This is consistent with a quiet, small project but provides little evidence of active community maintenance.
Composer is used for builds, but no security scanning tools were detected, leaving a modest gap in repository security hygiene.
The repository has no security policy, reducing transparency about vulnerability reporting and response procedures.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
enqueue/dsn Version ^0.10 | — | — |
google/cloud-pubsub Version ^1.4.3 | — | — |
queue-interop/queue-interop Version ^0.8 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.