Multi-transport messaging for Redis, Kafka, RabbitMQ, and Database with automatic serialization and consumer groups; a building block of the open-source foundation that Jardis-generated DDD code runs on
66%
Total Score
caution
Usable with caveats: one maintainer and a risky GitHub Actions workflow reduce confidence.
All 7 commits in the last 3 months came from one contributor, leaving little demonstrated maintenance redundancy. Organization backing partly compensates because responsibility can be handed off, but no second active contributor is shown.
The linked repository has no security policy, which reduces transparency for reporting and handling vulnerabilities in a package that supports several network-facing transports.
The audit found a high-confidence template-injection issue in auto-release.yml, plus all 7 action references are unpinned and one workflow grants top-level write access. No untrusted checkout or special dangerous trigger was found, so this is a meaningful hygiene and release-integrity concern rather than a severe standalone verdict.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
jardissupport/contracts Version ^1.0 || ^2.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.