Unfit to use for a new dependency: Packagist marks the package abandoned and names a replacement. Recent releases and a maintained, matching repository provide some evidence of activity, but they do not offset the package-level deprecation.
22%
Total Score
50
88
50
Packagist marks the entire package as abandoned and recommends `kafka-bus/messages` as its replacement. This is a severe adoption risk even though the specific release is not separately withdrawn.
One of five workflows uses pull_request_target, creating elevated workflow risk, but no untrusted checkout or script-injection patterns were detected. The risk is limited rather than severe.
There were no commits and no active maintainers in the last 3 months, despite the repository having been pushed about 3 months ago. This suggests current maintenance may have stalled and adds abandonment risk.
No security policy was found in the repository. For a library handling serialized Kafka messages, this reduces transparency around vulnerability reporting.
Three workflows omit top-level token permissions and two workflows request write access. This is weaker least-privilege hygiene, although the collected workflow data shows no untrusted checkout or script-injection issue.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
webmozart/assert Version ^1.11|^2.0 | — | — |
micromus/kafka-bus Version ^1.0.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.