The source has tests, release notes, a clear MIT license, and recent registry activity. Its workflow audit also found a high-confidence bot check problem and every action reference is unpinned, adding operational risk.
22%
Total Score
50
79
50
Packagist marks the entire package as abandoned and names kafka-bus/messages as the replacement, making this release unsuitable for a new dependency despite other healthy signals.
The repository recorded no commits and no active maintainers in the last 3 months, indicating that source maintenance has recently stopped.
The repository name does not match this package and its README does not mention the package, so the package-to-source relationship is unclear and may reflect repository piggy-backing.
All 12 analyzed action references are unpinned, and a high-confidence bot-conditions finding affects the Dependabot auto-merge workflow. The pull_request_target trigger has no untrusted checkout or script-injection sink, so this is operational hygiene risk rather than a standalone severe workflow risk.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
webmozart/assert Version ^1.11|^2.0 | — | — |
micromus/kafka-bus Version ^1.0.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.