The package includes repository tests, a changelog, MIT licensing, and Dependabot scanning. Its workflow audit also finds a high-confidence bot-condition issue, with all action references unpinned.
12%
Total Score
63
100
56
25
Packagist marks the entire package as abandoned, with no replacement package provided; this is a severe adoption risk beyond a single withdrawn release.
Only six releases exist, and the latest was about 20 months before collection with no releases in the last 12 months, indicating prolonged inactivity.
There were zero commits and zero active maintainers in the last three months, reinforcing the release inactivity and archived-repository concerns.
The linked source repository is archived, which strongly indicates the project is no longer intended for ongoing maintenance even though it was pushed in April 2026.
The audit found a high-confidence bot-condition issue in the Dependabot auto-merge workflow, and all 12 action references are unpinned; two workflows also grant top-level write permissions, increasing workflow maintenance and supply-chain exposure.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
micromus/kafka-bus Version ^0.6.7 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.