Recent publishing is offset by no commits or active maintainers in the last three months. Tests and a clear source tree help, but the proprietary license and absent README add adoption friction.
62%
Total Score
50
100
75
83
The manifest declares a proprietary license, so the release is licensed, but that creates legal and adoption constraints for projects expecting an open-source dependency.
The package and repository contain tests, which supports basic engineering maturity. The missing README is a small usability gap for a library consumers must integrate.
The repository recorded zero commits and zero active maintainers in the last three months, despite 12 registry releases in the last year; this weakens confidence in ongoing maintenance.
The repository uses Make and Composer, but no security-scanning tools were detected, leaving a modest process gap.
No repository security policy was found, reducing transparency about vulnerability reporting and response.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
micro-module/base Version ^0.9 || ^0.10 || ^0.11 || ^0.12 || ^0.13 || ^0.14 || ^0.15 | — | — |
micro-module/saga Version ^0.6 || ^0.7 | — | — |
micro-module/alerting Version ^0.7 || ^0.8 | — | — |
micro-module/broadway Version ^2.6 | — | — |
micro-module/job-queue Version ^0.10 || ^0.11 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.