The source repository remains active, with two contributors sharing recent commits, tests, and security scanning. The package is still a risky choice because its registry status withdraws the package and its last registry release was about four years ago.
45%
Total Score
100
75
50
The registry marks the entire package as abandoned, not merely this release, which is a serious adoption risk. The listed replacement is the same package name, so it does not provide a clear migration path.
The latest registry release was about four years ago, with no releases in the last 12 months. Its long history and 52 releases show maturity, but they do not offset the extended release gap.
The repository has no published security policy, which makes vulnerability reporting less transparent. This is a secondary concern because repository activity and security scanning are present.
The single workflow was fully analyzed with no reported audit findings or unsafe untrusted-code paths. However, both action references are unpinned, leaving a minor supply-chain hygiene gap.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
illuminate/queue Version ^8.0 | — | — |
php-amqplib/php-amqplib Version ^2.12|^3.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.