The package includes tests, a changelog, build tooling, and security scanning, with nine releases in the last year. Confirm that the proprietary terms and repository ownership fit your project before adoption.
60%
Total Score
50
81
50
The manifest declares a proprietary license, with no detected license text or license file in the package or repository. This creates a real adoption and transparency concern for an open-source dependency.
The repository recorded zero commits and zero active maintainers in the last three months. Frequent registry releases partly compensate, but the absence of observed source activity weakens confidence in current maintenance.
The repository name does not match the package name, and no README mention was found. That mismatch may be ordinary for a subpackage, but without a confirming README reference it creates uncertainty about repository ownership.
No security policy is present in the repository. This is a transparency gap, though it is less serious because security scanning is reported elsewhere.
Version v0.9.0 is not a stable major release, so compatibility may still change before 1.0. It is not marked as a prerelease, which partly offsets the concern.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
psr/log Version ^1.1 || ^2.0 || ^3.0 | — | — |
beberlei/assert Version ^3.3 | — | — |
micro-module/base Version ^0.9 || ^0.10 || ^0.11 || ^0.12 || ^0.13 || ^0.14 || ^0.15 | — | — |
micro-module/enqueue Version ^0.10 | — | — |
micro-module/broadway Version ^2.3 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.