The source repository is active enough to provide tests, release notes, and a security policy, and the package is MIT-licensed. However, all eight workflow actions are unpinned, and the registry marks this package abandoned in favor of contributte/rabbitmq; use the replacement instead.
35%
Total Score
50
67
83
Packagist marks the entire package as abandoned and names contributte/rabbitmq as its replacement, making this release a poor choice for a new dependency.
The package has 50 releases over more than nine years, but none in the last 12 months; this indicates the registry package is no longer being maintained as a release line.
The linked repository recorded no commits and no active maintainers in the last three months, which weakens confidence in ongoing maintenance despite its non-archived status.
The repository name does not match gamee/nette-rabbitmq and its README does not mention that package, so the linkage is not clearly established for this registry name.
All four workflows were analyzed without trigger or sink findings, but all eight action references are unpinned, leaving build behavior exposed to moving action versions.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
nette/di Version ^3.0.7 | — | — |
bunny/bunny Version ^0.5 | — | — |
nette/utils Version ^4.0.0 | — | — |
symfony/console Version ^6.4.2 || ^7.0.2 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.